diff-evidence-agent

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external data that could contain malicious instructions designed to subvert the agent's logic.
  • Ingestion points: The skill requires an implementation diff and test results (JSON or XML), both of which are external inputs that can be manipulated by an attacker (e.g., via code comments or test descriptions).
  • Boundary markers: There are no specific instructions or boundary markers defined to isolate the untrusted data or to instruct the agent to ignore any natural language instructions found within the diff or test results.
  • Capability inventory: The skill is authorized to read project documentation and write output files to the .agile-v/traceability/ directory. It does not possess network access or arbitrary command execution capabilities.
  • Sanitization: The instructions do not specify any sanitization, validation, or escaping procedures for the content extracted from the external inputs before it is used to generate reports and make a final decision.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:07 AM
Security Audit — agent-trust-hub — diff-evidence-agent