disk-hygiene

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the Bash tool to perform disk audits, measure directory sizes, and execute cleanup commands across various developer tool ecosystems.\n
  • Evidence: SKILL.md contains multiple bash blocks using heredocs to run commands like df, du, find, lsof, and stat on the local filesystem.\n
  • Evidence: Cleanup routines invoke powerful commands such as rm -rf, docker system prune, and npm cache clean --force to reclaim disk space.\n
  • Evidence: The skill includes logic to scan for running launchd services and their associated directories to prevent accidental deletion of artifacts used by active processes.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local filesystem, such as filenames, directory paths, and file metadata, which is then processed and presented to the user.\n
  • Ingestion points: Results from recursive find commands in Phase 3 (Forgotten File Detection) and Phase 4 (Downloads Triage) in SKILL.md are processed by the agent.\n
  • Boundary markers: There are no explicit delimiters or warnings to the agent to ignore potentially malicious instructions embedded in filenames or metadata.\n
  • Capability inventory: The skill has the ability to execute shell commands and modify the filesystem, which could be abused if an agent were influenced by malicious file content.\n
  • Sanitization: No explicit sanitization or filtering of file-based input is performed before the agent acts on the data.\n- [DYNAMIC_EXECUTION]: The skill provides instructions for generating and executing shell scripts at runtime to handle specific environment constraints.\n
  • Evidence: The Troubleshooting section in SKILL.md suggests using the Write tool to create scripts in /tmp and then executing them with bash to avoid issues with shell hooks like pueue.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 10:57 PM
Security Audit — agent-trust-hub — disk-hygiene