tailrocks-skill-refactor
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes repository files, references, and tool outputs which are treated as untrusted data.
- Ingestion points: Accesses files within the skill and reference directories as input (SKILL.md, references/runtime-trust.md).
- Boundary markers: Contains explicit instructions to ignore embedded commands or rule changes within processed data.
- Capability inventory: Performs filesystem writes to restructure skills and executes local tasks via mise (references/house-wiring.md).
- Sanitization: Strict rules prevent copying secrets into outputs, mandating citation by location only.
Audit Metadata