think-tank
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill facilitates remote execution by orchestrating specialist jobs on Substrate runners. It uses a job-creation tool to dispatch tasks to remote environments using specific harness types and configurable directory paths.\n- [COMMAND_EXECUTION]: The skill notes the availability of shell and filesystem tools such as bash, read, and write for session management and documentation updates.\n- [DATA_EXFILTRATION]: The skill is designed to transfer workspace data, including source code and internal artifacts, to remote runners for the purpose of research and review.\n- [PROMPT_INJECTION]: The skill provides an indirect prompt injection surface through the ingestion of external research findings and user input.\n
- Ingestion points: Specialist findings stored in workspace artifacts and user responses in the grill loop.\n
- Boundary markers: Present. The skill mandates that the agent distinguish evidence from interpretation and requires explicit human approval for all document updates.\n
- Capability inventory: High. Includes file system writes, shell access, and remote job creation.\n
- Sanitization: Absent. Specialist findings are not explicitly sanitized before being incorporated into the project documentation.
Audit Metadata