tailrocks-idea
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input ('a sentence, a paragraph, pasted notes') to generate roadmap items and repository content. Although it has a strict 'Capture, do not invent' rule and boundaries against execution, the ingestion of arbitrary text that is later committed to a shared repository creates a surface for multi-step injection attacks if the roadmap is processed by other automated tools.
- [COMMAND_EXECUTION]: Executes the vendor-provided script
bun <installed-plugin>/scripts/idea-capture.ts. This script is responsible for core repository operations including branching, staging, committing, and pushing code. This behavior is documented as the intended purpose of the skill within the 'tailrocks' delivery family. - [EXTERNAL_DOWNLOADS]: Mentions and relies on 'tailrocks' vendor resources such as
tailrocks-brainstorm,tailrocks-research, and specific schemas. These are recognized as legitimate vendor-owned resources and do not escalate the verdict. - [METADATA_POISONING]: The skill documentation includes specific instructions about its own safety and verification (e.g., 'Its one tailrocks.idea-capture/v1 receipt is the only success oracle'). These claims are treated as data and do not influence the independent security analysis.
Audit Metadata