skills/404kidwiz/mentions-api/graft/Gen Agent Trust Hub

graft

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the code repository it is indexing, which constitutes an untrusted data source.
  • Ingestion points: Data enters the agent's context through tools like graft ask (retrieval over the graph), graft grep (regex search over source files), and graft skeleton (parsing file signatures).
  • Boundary markers: The skill documentation does not specify the use of delimiters or specific instructions to the agent to ignore potentially malicious content embedded within the indexed source files.
  • Capability inventory: The skill provides the agent with capabilities to read file spans, perform exhaustive searches, and analyze repository-wide call graphs.
  • Sanitization: There are no mentioned mechanisms for sanitizing or filtering the source code content before it is presented to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 11:52 PM
Security Audit — agent-trust-hub — graft