overlay-governance

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill body and references include instructions to execute agent-harness governance check --repo-root . for validating repository markdown links and documentation structure.
  • [SAFE]: No obfuscation, credential exposure, or unauthorized network operations were detected. All described activities are project-local.
  • [SAFE]: Evaluated for indirect prompt injection attack surface: 1. Ingestion points: The skill processes project-local files including AGENTS.md and content within docs-ai/docs/**. 2. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified in the policy. 3. Capability inventory: Local command execution via the agent-harness utility. 4. Sanitization: No specific filtering or validation of external content is documented, though the tool is stated to ignore external URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 05:16 PM
Security Audit — agent-trust-hub — overlay-governance