password-auditor
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection attacks where malicious instructions could be embedded in audited files.
- Ingestion points: The agent is instructed to read and analyze data from the
filesystemandcodebase, including password policies, hashes, and breach databases. - Boundary markers: The instructions lack explicit delimiters or warnings to treat processed data as untrusted content.
- Capability inventory: The agent has access to the
filesystemandcodebasetools, providing a surface for injected instructions to interact with the user's environment. - Sanitization: There is no evidence of input validation, escaping, or filtering for the external content being processed.
Audit Metadata