paper-prototype

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes live data from external APIs, databases, and production files, which creates an attack surface for indirect prompt injection. Ingestion points: Step 2 involves acquiring real raw input from external APIs, live DB queries, and production files. Boundary markers: No delimiters or instructions are provided to the subagent to distinguish between data and instructions. Capability inventory: The agent is authorized to use curl, jq, sqlite3, and grep, and can write various file types to disk. Sanitization: There is no requirement for validation or sanitization of the external data before processing.
  • [COMMAND_EXECUTION]: The instructions explicitly permit the use of shell one-liners and command-line utilities such as curl, sqlite3, and jq to interact with live production systems for data acquisition and movement.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — paper-prototype