breadboard-reflection

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to read and analyze source code files, which serves as an ingestion point for untrusted data. This creates a surface for indirect prompt injection if the analyzed code contains malicious instructions designed to influence the agent's behavior. However, the skill provides no automated tools or scripts that would allow such instructions to be executed or escalated.
  • Ingestion points: The agent is instructed to "Read the implementation code" and "Find the relevant source files" (SKILL.md).
  • Boundary markers: No specific delimiters or warnings to ignore instructions within the code are provided.
  • Capability inventory: The skill suggests the agent should "Update the breadboard" and "Optionally update the code," implying file system write capabilities.
  • Sanitization: No sanitization or validation of the ingested code is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 06:18 PM
Security Audit — agent-trust-hub — breadboard-reflection