agent-native-repo-playbook
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits user-provided files such as AGENTS.md, STRUCTURE.md, and .github/workflows/, creating a surface where malicious instructions in the audited content could influence the agent's behavior.
- Ingestion points: Audited files including AGENTS.md, repo maps, and workflow configurations.
- Boundary markers: No explicit delimiters or isolation instructions for processing audited content are specified.
- Capability inventory: The skill can recommend changes, produce recommendations, and reference local scripts for execution.
- Sanitization: No sanitization of ingested content is defined in the instructions.
- [EXTERNAL_DOWNLOADS]: The source-manifest.md file references transcription artifacts hosted on storage.aipodcast.ing. While these appear to be vendor-managed resources (WIN), they originate from a third-party domain not included in the trusted vendors list.
- [COMMAND_EXECUTION]: The skill refers to executing local scripts like scripts/check-fast.sh and scripts/check-full.sh within the repository environment being audited, which is a potential risk if the audited repository contains malicious code.
Audit Metadata