state-model

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection and user argument interpolation surface identified.\n
  • Ingestion points: The skill ingests data from user-provided $ARGUMENTS and various repository source files, including routes, components, database schemas, and API endpoints.\n
  • Boundary markers: There are no boundary markers or delimiters defined in SKILL.md to isolate instructions from the ingested project data, nor are there instructions to disregard embedded commands.\n
  • Capability inventory: The agent has the capability to read project source files and metadata, and is explicitly instructed to write documentation to the local filesystem (docs/hci/state-model.md), including directory creation.\n
  • Sanitization: No content sanitization, validation, or escaping is performed on the ingested data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:52 PM
Security Audit — agent-trust-hub — state-model