skills/ykdz/skills/afk-slice-worker/Gen Agent Trust Hub

afk-slice-worker

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data such as task tickets, architecture records, and observation logs (docs/observations/). This data flow creates a surface for indirect prompt injection if the external sources contain malicious instructions intended to influence the agent's behavior. The skill provides mitigation by requiring adherence to strict 'Contracts' and authoritative sources, but the ingestion point remains an inherent risk.
  • Ingestion points: Reads task tickets, design specifications (references/design-brief.md), and observation ledgers (references/observations.md).
  • Boundary markers: Uses specific completion tokens (READY_FOR_ACCEPTANCE, INCOMPLETE, READY_FOR_HUMAN) to define the end of an action slice.
  • Capability inventory: The agent has capabilities for reading/writing files, managing git worktrees/branches, and executing commands through a prototype tool.
  • Sanitization: While the skill mandates evidence-based validation, it does not explicitly instruct on sanitizing or escaping the content of ingested materials.
  • [DYNAMIC_EXECUTION]: The references/design-brief.md file outlines a 'Prototype Contract' that permits the execution of logic and UI prototypes. This process involves the creation of temporary processes, network ports, and task runners. Although this is a form of dynamic execution, the skill instructions mandate a strict lifecycle including isolation in separate worktrees and mandatory cleanup of all temporary resources to prevent environment contamination.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 02:53 AM