focused-fix
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality requires it to read, trace, and modify files within a user's project, which could contain malicious instructions designed to subvert the agent's logic.
- Ingestion points: In Phase 1 (Scope) and Phase 2 (Trace), the agent is instructed to read every file in a target folder and trace imports across the entire codebase. It also reads logs and git history in Phase 3 (Diagnose).
- Boundary markers: The protocol does not include explicit instructions or markers to distinguish executable code or data from potentially malicious natural language instructions embedded in comments or strings.
- Capability inventory: The skill possesses significant capabilities, including the ability to overwrite project files (Phase 4), execute test suites, and run shell commands for dependency tracing and git history analysis.
- Sanitization: There is no evidence of sanitization or safety-filtering applied to the content of the files being analyzed before the agent incorporates that information into its diagnosis and fixing plan.
Audit Metadata