bootstrap

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax in SKILL.md to execute shell commands (echo, cat) to dynamically inject the local directory path and version information into the agent's context. These commands are used for internal configuration and do not involve user-controlled input.
  • [COMMAND_EXECUTION]: The skill instructions involve the agent performing file system operations, including reading architecture documentation and writing numerous files and directories to create the project structure. These actions are aligned with the stated purpose of scaffolding a project.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) as it processes user-provided data such as project names and configuration preferences to generate file content. Ingestion points: User input and local architecture files. Boundary markers: Absent. Capability inventory: File-write (scaffold monorepo). Sanitization: Not explicitly defined. The risk is considered low and standard for scaffolding functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 06:07 AM
Security Audit — agent-trust-hub — bootstrap