x9-context-files-generator
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted repository data to generate or update instructions. 1. Ingestion points: The agent reads existing
AGENTS.mdandREADME.mdfiles. 2. Boundary markers: Instructions emphasize preserving user-owned rules and using surgical merge strategies. 3. Capability inventory: The skill can write files and execute local commands. 4. Sanitization: It includes strict rules against personal paths and requires explicit authorization for dangerous commands. - [COMMAND_EXECUTION]: The skill permits the execution of shell commands found within the repository for validation purposes, though it restricts this to safe and local operations by default.
- [SAFE]: The skill implements privacy best practices by explicitly forbidding the inclusion of personal absolute paths in committed repository files.
- [SAFE]: External references are limited to trusted academic domains (arxiv.org) and other skill tools within the same author namespace.
Audit Metadata