skills/yuen30/my-skills/my-agent/Gen Agent Trust Hub

my-agent

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The opencode/AGENTS.md configuration file instructs the agent to automatically download and install missing dependencies using the command npx skills add <skill-name> immediately without manual intervention.
  • [COMMAND_EXECUTION]: The SKILL.md file provides several copy-pasteable shell commands (mkdir, cp, diff) for the user to execute to restore configuration files to specific local directories (~/.claude/agents/, ~/.codex/, and ~/.config/opencode/).
  • [INDIRECT_PROMPT_INJECTION]: The skill's persona definitions (specifically agents/boss.md and agents/note.md) ingest untrusted data from the repository, such as git logs, project memory files, and GitHub issue lists. This metadata could potentially be poisoned with instructions that influence the agent's behavior.
  • Ingestion points: agents/boss.md (reads git log, MEMORY.md), agents/note.md (reads gh issue list).
  • Boundary markers: Absent. The instructions do not define specific delimiters for separating repository metadata from agent instructions.
  • Capability inventory: gh issue create, Read, Write, Edit, Bash (available in agents/note.md, agents/boss.md).
  • Sanitization: Absent. There are no explicit instructions to sanitize or escape data read from the repository logs or issues.
  • [DATA_EXFILTRATION]: The agents/note.md persona is programmed to automatically create, comment on, and close GitHub issues to report task progress. While designed for reporting purposes, this capability involves sending repository status and summary information to an external service (GitHub).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:58 AM
Security Audit — agent-trust-hub — my-agent