skills/yan-labs/yan-skills/autopilot/Gen Agent Trust Hub

autopilot

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from user commands and external issue trackers (GitHub, GitLab, Jira) to automate complex development tasks.\n
  • Ingestion points: Fuzzy user commands, project-specific rule files (CLAUDE.md, AGENTS.md), and external issue descriptions/comments.\n
  • Boundary markers: The skill uses structural JSON blocks wrapped in HTML comments for internal tracking and encourages self-contained briefs for subagents.\n
  • Capability inventory: Extensive capabilities including file system modification, shell command execution (tsc, lint, build), and network operations (git push, gh-cli).\n
  • Sanitization: The skill provides explicit instructions to avoid persisting sensitive data (secrets, tokens) and advocates for using white-listed fields.\n- [COMMAND_EXECUTION]: The skill executes various development tools and shell commands such as git, gh-cli, npx, tsc, and lint to perform code modification, testing, and deployment processes.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installation and updates using 'npx skills add yan-labs/yan-skills', which fetches code from the vendor-owned platform skills.sh.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 10:10 AM
Security Audit — agent-trust-hub — autopilot