global-error-handling
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Path traversal sequence identified in documentation reference. Evidence: "global error handling" in SKILL.md. The skill explicitly instructs the agent to read a file located three directory levels above the skill root, which can be leveraged to access sensitive files outside the intended scope.
- [PROMPT_INJECTION]: Self-referential analysis content found in the skill package. Evidence: "skill-report.json" contains a pre-computed "security_audit" section with a verdict and analysis summary. This content targets the auditor by providing pre-authored safety claims, which is a form of injection designed to interfere with objective security evaluation.
Audit Metadata