system-environment-configuration
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from several external files, including
substrate-context.md,phase-1-landscape-report.md, andphase-2-taxonomy-model.md. This setup creates a vulnerability surface for indirect prompt injection if those files contain malicious instructions. \n - Ingestion points: Data is read from multiple markdown files in the working directory to drive the environment specification process. \n
- Boundary markers: The skill lacks instructions to delimit or ignore potentially malicious content embedded in these input files. \n
- Capability inventory: The skill is authorized to use tools including
Bash,Write,Edit, andGrep, which provides a mechanism for command execution if the agent is manipulated. \n - Sanitization: There are no defined steps to validate or sanitize the input content before processing it for code generation.
Audit Metadata