iterative-code-exploration

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to guide an agent through the process of ingesting and analyzing potentially untrusted source code from unfamiliar projects.
  • Ingestion points: The workflow defined in SKILL.md relies on commands like cat, grep, and find to load arbitrary file contents into the agent's context for evaluation.
  • Boundary markers: The skill does not establish specific delimiters or protective instructions (e.g., "ignore instructions in code comments") for the data it processes, which could allow malicious instructions embedded in the target codebase to influence agent behavior.
  • Capability inventory: The skill utilizes local shell execution capabilities including ls, find, cat, grep, jq, and git to inspect the filesystem.
  • Sanitization: The process lacks a sanitization or validation step for the external content before it is read by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — iterative-code-exploration