focused-fix

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality requires it to read, trace, and modify files within a user's project, which could contain malicious instructions designed to subvert the agent's logic.
  • Ingestion points: In Phase 1 (Scope) and Phase 2 (Trace), the agent is instructed to read every file in a target folder and trace imports across the entire codebase. It also reads logs and git history in Phase 3 (Diagnose).
  • Boundary markers: The protocol does not include explicit instructions or markers to distinguish executable code or data from potentially malicious natural language instructions embedded in comments or strings.
  • Capability inventory: The skill possesses significant capabilities, including the ability to overwrite project files (Phase 4), execute test suites, and run shell commands for dependency tracing and git history analysis.
  • Sanitization: There is no evidence of sanitization or safety-filtering applied to the content of the files being analyzed before the agent incorporates that information into its diagnosis and fixing plan.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:17 PM