skills/dagster-io/erk/ci-iteration/Gen Agent Trust Hub

ci-iteration

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands via make targets and a repository-specific tool named erk to perform CI tasks and synchronization. These operations are fundamental to the skill's stated purpose of automating development workflows.
  • [PROMPT_INJECTION]: The skill's workflow involves reading and parsing output from external tools such as pytest, ruff, and ty, creating an inherent surface for indirect prompt injection. Ingestion points: Error logs and tool outputs from the development environment are ingested by the agent (Workflow Step 2). Boundary markers: The instructions lack specific guidance on using delimiters or ignore-behavior markers to differentiate tool output from valid instructions. Capability inventory: The parent agent has the capability to read/edit project files and execute further shell commands based on its interpretation of the ingested logs. Sanitization: No validation or sanitization mechanisms are described for the ingested tool output before it influences the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 03:21 AM