401-cleanup
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process project files defined by a user-provided scope, creating a surface for indirect prompt injection where malicious instructions hidden in the codebase could be executed by the agent during the cleanup phase.
- Ingestion points: Source code files, test files, and repository documentation accessed via the
scope-anchorinSKILL.md. - Boundary markers: The skill employs several mitigations, including a mandatory choice between
source-cleanup-onlyortest-cleanup-only, the use of a 'Cleanup ledger' to track forbidden modules, and 'Task packets' that restrict the context provided to subagents. - Capability inventory: The workflow utilizes
@coderfor file modification and@validatorfor executing build, lint, and test commands as described in Phase 0 and Phase 3. - Sanitization: The instructions do not specify any sanitization, filtering, or escaping of the content read from the repository files before it is passed to the LLM subagents.
Audit Metadata