agree-on-everything

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from the local codebase to generate implementation plans, creating a surface where malicious comments or code in project files could influence planning output. 1. Ingestion points: Local codebase analysis. 2. Boundary markers: Absent. 3. Capability inventory: Writing plan files to doc/plans/ and invoking the /build-alone skill. 4. Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: The skill checks for the presence of the /build-alone skill from the triskweline/skills repository. This is a reference to a toolset provided by the same vendor and is used to delegate implementation tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 09:05 AM
Security Audit — agent-trust-hub — agree-on-everything