skills/terseai/terse/terse-create/Gen Agent Trust Hub

terse-create

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it processes untrusted workspace data and user arguments to generate new workflow logic. This is an expected behavior for a code-generation tool.
  • Ingestion points: The skill reads local files including src/terse.generated.ts and src/terse.jobs.ts, and accepts user input via the $ARGUMENTS variable in SKILL.md.
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore' instructions when reading workspace content, though the intent is technical context retrieval.
  • Capability inventory: The agent is authorized to execute the terse CLI, write files to the project structure, and spawn specialized research subagents.
  • Sanitization: The instructions focus on technical accuracy and type safety but do not include specific sanitization or filtering logic for instructions that might be embedded in ingested workspace files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 03:54 PM
Security Audit — agent-trust-hub — terse-create