skills/toy-crane/skills/babysit-specs/Gen Agent Trust Hub

babysit-specs

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and processing project specifications, prototypes, decision contracts, and source code. These files represent untrusted ingestion points where malicious instructions could be embedded to influence the agent's behavior during the revision process.
  • Ingestion points: Processes content from docs/specs/, docs/decisions/, GLOSSARY.md, and various source code surfaces.
  • Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore' warnings for the data it processes.
  • Capability inventory: The agent has the ability to read and write to the filesystem, access Git history, and potentially invoke other tools like split-into-tasks or build-prototype based on the data it reads.
  • Sanitization: No explicit sanitization or validation of the ingested data is described.
  • [DYNAMIC_EXECUTION]: The skill is instructed to execute the project's own code to facilitate UI comparison between prototypes and the current product state.
  • Evidence: SKILL.md contains the instruction: "Render the linked prototype.html and compare its screens and states with the current product surface, running the product when the repository exposes it."
  • Security Note: This capability requires the agent to run scripts (e.g., npm run dev) defined in the project repository. If a repository is compromised or contains malicious build/start scripts, this could lead to the execution of arbitrary code in the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 04:12 PM
Security Audit — agent-trust-hub — babysit-specs