reuse-first
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to search through and process existing source code to identify reusable helpers. This behavior creates an attack surface where maliciously crafted content (e.g., in comments or function bodies) within the repository could attempt to influence the agent's decision-making or code-generation process.
- Ingestion points: The agent is directed to read and analyze files in the current package, neighboring packages, and shared utility directories (
shared,utils,lib) to find matching logic as described in Procedure 2. - Boundary markers: There are no specific instructions or delimiters provided to the agent to treat the discovered code as potentially untrusted or to ignore any embedded directives within that code.
- Capability inventory: The skill allows the agent to read file contents and perform code modifications, including extracting logic, replacing existing code blocks, and writing new utility files to the filesystem based on Procedures 3 and 4.
- Sanitization: The procedures do not include steps for validating or sanitizing the content found during the search before it is imported or used to extend existing functions.
- [NO_CODE]: The skill consists entirely of instructional documentation and does not include any accompanying scripts or executable code.
Audit Metadata