global-coding-style
Warn
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [DATA_EXFILTRATION]: The skill contains a relative path traversal link that attempts to access documentation located outside the skill's root directory. Path traversal sequences can be exploited to read sensitive system or configuration files beyond the intended scope. Evidence:
[global coding style](../../../agent-os/standards/global/coding-style.md)inSKILL.mdat line 30. - [INDIRECT_PROMPT_INJECTION]: The skill's
skill-report.jsonfile contains self-referential safety claims designed to override automated security analysis. 1. Ingestion points:skill-report.jsonmetadata fields. 2. Boundary markers: Absent. 3. Capability inventory: The skill is intended for code formatting and analysis, requiring file system access and execution of tools like Laravel Pint and Larastan. 4. Sanitization: Absent. - [METADATA_POISONING]: The
skill-report.jsonfile contains contradictory and deceptive metadata. It identifies high-severity risks while simultaneously declaring a 'safe' verdict, which can mislead users about the actual security posture of the skill.
Audit Metadata