not-your-babysitter

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong steering instructions to implement a high-autonomy persona, directing the agent to be the primary "decision-maker" and to "interrupt almost never." This shifts control to the agent and reduces standard user oversight during task execution.- [PROMPT_INJECTION]: The skill workflow creates a surface for indirect prompt injection by design. Ingestion points: The agent is instructed to ingest untrusted data from web search results, MCP documentation servers, and third-party CLI outputs (SKILL.md). Boundary markers: The instructions lack definitions for boundary markers or requirements to ignore instructions embedded within the processed external data. Capability inventory: The agent is authorized to execute CLI commands, perform file-system operations for state management, and run build/test processes. Sanitization: There are no instructions for sanitizing or validating external content before it is processed. Mitigation: The risk is mitigated by mandatory checkpoints requiring user approval for all destructive or irreversible actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:22 AM
Security Audit — agent-trust-hub — not-your-babysitter