ledger-tasks-yylo

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the 'yy' CLI tool to perform various task management actions, which involves executing shell commands to interact with the ledger system as defined in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses task data from the ledger board, which could contain instructions from untrusted sources. 1. Ingestion points: SKILL.md defines retrieval commands such as 'yy ledger get', 'yy ledger search', and 'yy ledger list'. 2. Boundary markers: No delimiters or ignore instructions are present in SKILL.md to separate task data from instructions. 3. Capability inventory: SKILL.md authorizes shell commands via the enable-shell-directives setting and provides a set of CLI subcommands for system interaction. 4. Sanitization: The instructions in SKILL.md do not specify any sanitization or escaping of task-derived content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 11:13 PM
Security Audit — agent-trust-hub — ledger-tasks-yylo