crushable-wingman

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local Python script (scripts/wingman_store.py) to handle file persistence for its profile and memory systems. This script performs basic file I/O operations within a dedicated state directory and is a standard component of the skill's functionality.
  • [PROMPT_INJECTION]: While the skill processes external chat data and screenshots (Indirect Prompt Injection surface), it implements a mitigation strategy in references/ocr-extraction.md. The agent is instructed to present an extracted transcript for user confirmation before performing any analysis or generating replies, which helps prevent the automatic execution of instructions that might be embedded in the provided images.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 06:11 PM
Security Audit — agent-trust-hub — crushable-wingman