system-environment-configuration

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from several external files, including substrate-context.md, phase-1-landscape-report.md, and phase-2-taxonomy-model.md. This setup creates a vulnerability surface for indirect prompt injection if those files contain malicious instructions. \n
  • Ingestion points: Data is read from multiple markdown files in the working directory to drive the environment specification process. \n
  • Boundary markers: The skill lacks instructions to delimit or ignore potentially malicious content embedded in these input files. \n
  • Capability inventory: The skill is authorized to use tools including Bash, Write, Edit, and Grep, which provides a mechanism for command execution if the agent is manipulated. \n
  • Sanitization: There are no defined steps to validate or sanitize the input content before processing it for code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — system-environment-configuration