Oathe Security Badge

Is dietrichgebert/ponytail safe?

Yes. dietrichgebert/ponytail is safe to install. Oathe's behavioral security audit gave the ponytail skill by dietrichgebert a trust score of 87/100 with 5 findings, none critical or high. Report updated

https://github.com/dietrichgebert/ponytail

87
SAFE

Is dietrichgebert/ponytail safe to install?

Ponytail is a legitimate developer productivity skill that enforces minimal/YAGNI coding practices across agent interactions. No malicious behavior was detected: canary honeypots were untouched (pre-clone accesses at 09:44:49 match the monitoring infrastructure setup, 6 seconds before the GitHub clone at 09:44:55), network activity was limited to GitHub and Ubuntu system infrastructure, and no malicious install-time execution, git hooks, submodules, or data exfiltration attempts were found. Minor concerns include the persistent 'ACTIVE EVERY RESPONSE' mode overriding default agent behavior, hook scripts that write flag files and modify Claude's settings.json on every session start, and the Kiro always-include directive — all documented, intentional features with proper deactivation mechanisms and a clean uninstall script.

What security issues were found in dietrichgebert/ponytail?

Category Scores

Prompt Injection 77/100 · 30%
Data Exfiltration 92/100 · 25%
Code Execution 85/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 87/100 · 5%

Findings (5)

LOW Persistent agent persona modification across all responses -15 ▶

The main ponytail skill uses 'ACTIVE EVERY RESPONSE' to enforce its coding philosophy indefinitely for every agent response, overriding the agent's default behavior for all coding tasks until explicitly deactivated. While this is the documented intended behavior with a clear deactivation path, it constitutes a persistent behavioral override affecting all subsequent interactions without per-request confirmation.

LOW Kiro steering file forces always-on injection -5 ▶

The .kiro/steering/ponytail.md file contains 'inclusion: always' in its YAML frontmatter, instructing Kiro IDE to inject the ponytail ruleset into every conversation turn automatically. Users who install this skill for on-demand use may not expect it to activate without an explicit invocation command.

INFO External URL reference in help skill -3 ▶

The ponytail-help skill references the project GitHub homepage for extended documentation. This is benign but agents equipped with web-browsing tools could follow this reference, and it represents an outbound pointer to third-party content.

INFO Hook scripts write flag files and modify agent settings.json -15 ▶

The lifecycle hook scripts write .ponytail-active flag files to platform-specific user directories (~/.claude/, ~/.cursor/, PLUGIN_DATA) and modify the Claude Code settings.json to install a custom statusline command. These are documented features with a working uninstall path, but they represent persistent filesystem changes outside the skill directory that survive across sessions.

INFO Whole-repository grep scanning exposes code comment contents -8 ▶

The ponytail-debt skill instructs the agent to execute 'grep -rnE (# | //) ?ponytail: .' across the entire repository and output all matching comments including their ceiling descriptions and upgrade paths. The ponytail-audit skill similarly scans the whole codebase. While these are intentional features, they cause the agent to read and potentially output sensitive architectural details embedded in developer comments.

Should I install dietrichgebert/ponytail?

Oathe's verdict for dietrichgebert/ponytail is SAFE with a trust score of 87/100. Recommendation: Install.