agree-on-everything
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from the local codebase to generate implementation plans, creating a surface where malicious comments or code in project files could influence planning output. 1. Ingestion points: Local codebase analysis. 2. Boundary markers: Absent. 3. Capability inventory: Writing plan files to doc/plans/ and invoking the /build-alone skill. 4. Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: The skill checks for the presence of the /build-alone skill from the triskweline/skills repository. This is a reference to a toolset provided by the same vendor and is used to delegate implementation tasks.
Audit Metadata