tailrocks-improve-plan

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core logic involves processing untrusted repository content, reports, and web content. While it includes explicit 'Runtime trust' guidelines (references/runtime-trust.md) to treat this content as data rather than instructions, the attack surface for indirect injection remains inherent to its design.
  • [METADATA_POISONING]: The skill uses detailed instructions to manage metadata within plans/README.md and YAML frontmatter. While not deceptive in intent, these mechanisms could be targeted to influence agent behavior through structural manipulation or 'rejection' row poisoning.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:11 PM
Security Audit — agent-trust-hub — tailrocks-improve-plan