agents-md-pro
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it performs automated analysis of untrusted content from the repository, such as
README.mdfiles, source code, and configuration files, to generate its output. - Ingestion points: The skill reads
package.json,.eslintrc,README.md, and key source files as part of theCREATE,UPDATE, andVALIDATEworkflows inreferences/workflows.md. - Boundary markers: Absent. There are no instructions to wrap external content in delimiters or to ignore embedded instructions during the codebase analysis phase.
- Capability inventory: The skill is capable of reading repository files and writing/overwriting
AGENTS.mdfiles. - Sanitization: Absent. The workflows do not specify any validation or sanitization of the content extracted from the files before processing it.
Audit Metadata