global-error-handling

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Path traversal sequence identified in documentation reference. Evidence: "global error handling" in SKILL.md. The skill explicitly instructs the agent to read a file located three directory levels above the skill root, which can be leveraged to access sensitive files outside the intended scope.
  • [PROMPT_INJECTION]: Self-referential analysis content found in the skill package. Evidence: "skill-report.json" contains a pre-computed "security_audit" section with a verdict and analysis summary. This content targets the auditor by providing pre-authored safety claims, which is a form of injection designed to interfere with objective security evaluation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 07:57 AM
Security Audit — agent-trust-hub — global-error-handling