spring-boot-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a workflow where the agent analyzes external requirements and executes project tests. This architecture presents a surface where instructions embedded in external data could influence agent actions during the build and test phases.
- Ingestion points: Core workflow in
SKILL.md(Analyze requirements). - Boundary markers: Absent; there are no explicit instructions for the agent to ignore or delimit instructions embedded within the analyzed requirements.
- Capability inventory: Execution of shell commands (
./mvnw test,./gradlew test) specified inSKILL.md. - Sanitization: Absent; there is no specific process defined to sanitize or validate the external requirements data before it influences the workflow.
- [COMMAND_EXECUTION]: The skill directs the agent to execute standard build tool commands (
./mvnw test,./gradlew test) and Actuator health check validations. While these are necessary for the stated purpose of building and verifying Java applications, they involve the execution of scripts and binaries within the project environment. - [CREDENTIALS_UNSAFE]: The skill documentation explicitly mandates the externalization of secrets using environment variables or Spring Cloud Config, demonstrating best practices for secret management. Examples provided use environment variable placeholders like
${GIT_PASSWORD}rather than hardcoded credentials.
Audit Metadata