reset

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands such as mkdir, mv, and rm. These operations are strictly limited to the .fpf/ subdirectory and are used for managing the session state of the 'FPF reasoning cycle'.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves the manipulation of files that may contain externally generated content (hypotheses). While these files are moved or deleted, the skill does not explicitly instruct the agent to interpret or execute instructions found within those files, reducing the risk of indirect injection.
  • Ingestion points: Files located in .fpf/knowledge/, .fpf/evidence/, and .fpf/decisions/ (SKILL.md).
  • Boundary markers: None explicitly defined for file content.
  • Capability inventory: File system operations (mkdir, mv, rm) via shell commands.
  • Sanitization: Not applicable as content is not being parsed or executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — reset