x9-context-files-generator

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted repository data to generate or update instructions. 1. Ingestion points: The agent reads existing AGENTS.md and README.md files. 2. Boundary markers: Instructions emphasize preserving user-owned rules and using surgical merge strategies. 3. Capability inventory: The skill can write files and execute local commands. 4. Sanitization: It includes strict rules against personal paths and requires explicit authorization for dangerous commands.
  • [COMMAND_EXECUTION]: The skill permits the execution of shell commands found within the repository for validation purposes, though it restricts this to safe and local operations by default.
  • [SAFE]: The skill implements privacy best practices by explicitly forbidding the inclusion of personal absolute paths in committed repository files.
  • [SAFE]: External references are limited to trusted academic domains (arxiv.org) and other skill tools within the same author namespace.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 07:41 AM
Security Audit — agent-trust-hub — x9-context-files-generator