poteto-mode
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a procedural style guide and workflow orchestrator. It incorporates non-negotiable safety pauses for irreversible operations such as deployments, data deletion, or force-pushing to shared branches, which mitigates the risk of autonomous errors.- [SAFE]: No evidence of obfuscation, credential exposure, or unauthorized remote code execution was found. External references are limited to local playbook files and integrated platform tools like the cursor-team-kit plugin.- [INDIRECT_PROMPT_INJECTION]: The skill presents an inherent surface for indirect prompt injection through its use of subagents and model context protocol (MCP) tools to process external data. However, the instructions are oriented toward professional software engineering practices and architectural rigor.
- Ingestion points: The agent reads user-provided tasks and local markdown files (playbooks).
- Boundary markers: The agent is instructed to trace every decision to a specific principle, providing a reasoning chain, though it lacks formal delimiters for external data.
- Capability inventory: The skill utilizes subagent spawning, MCP tool access, and file system modification.
- Sanitization: The skill relies on platform-level model guardrails and explicit subagent configurations (e.g., poteto-agent type).
Audit Metadata