research

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to ingest and process untrusted external data from primary sources like official documentation, source code, and first-party APIs.
  • Ingestion points: External sources including official documentation, source code, specifications, and first-party APIs (SKILL.md).
  • Boundary markers: The instructions lack explicit boundary markers or directives for the agent to ignore instructions that might be embedded within the source materials.
  • Capability inventory: The agent possesses the capability to write findings to Markdown files within the repository (SKILL.md).
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the content retrieved from external sources before it is processed or stored.
  • [NO_CODE]: The skill consists entirely of instructional text and metadata, containing no executable scripts or binary files, which minimizes the risk of direct remote code execution from the skill's own content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 06:06 PM
Security Audit — agent-trust-hub — research