skills/yzfly/skills/cto/Gen Agent Trust Hub

cto

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill includes an explicit instruction to update itself by executing a shell command to download and overwrite its own source files from a remote repository. While the source (https://github.com/yzfly/CTO-Skills) corresponds to the author's infrastructure, this mechanism enables remote and autonomous modification of the agent's logic and instructions without user review of the new content.
  • Evidence: Instruction in SKILL.md to perform a git clone and overwrite the current skill directory when a user requests an update.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates in 'Brownfield mode,' where it reads and analyzes existing codebases to provide senior-level judgments and execute code changes. This process involves ingesting untrusted data from external repositories, creating a surface for indirect prompt injection if malicious instructions are placed in analyzed files.
  • Ingestion points: Analyzes project code, commit history (git log), and architectural documentation using Read and grep (specified in SKILL.md).
  • Boundary markers: The instructions lack requirements for using delimiters or explicit 'ignore embedded instructions' warnings when processing project content.
  • Capability inventory: The skill has high-risk permissions including writing code, updating ADRs, and preparing pull requests (specified in SKILL.md).
  • Sanitization: No sanitization or escaping of ingested data is prescribed before interpolation into the agent context.
  • [COMMAND_EXECUTION]: The skill is instructed to perform environment-altering shell commands, such as git clone, to manage its own lifecycle and update its instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 10:40 AM
Security Audit — agent-trust-hub — cto