agents-md-pro

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it performs automated analysis of untrusted content from the repository, such as README.md files, source code, and configuration files, to generate its output.
  • Ingestion points: The skill reads package.json, .eslintrc, README.md, and key source files as part of the CREATE, UPDATE, and VALIDATE workflows in references/workflows.md.
  • Boundary markers: Absent. There are no instructions to wrap external content in delimiters or to ignore embedded instructions during the codebase analysis phase.
  • Capability inventory: The skill is capable of reading repository files and writing/overwriting AGENTS.md files.
  • Sanitization: Absent. The workflows do not specify any validation or sanitization of the content extracted from the files before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 12:11 PM