tech-debt-tracker
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: Hardcoded credentials and secrets were identified within the sample codebase files provided in the skill's assets. This includes plaintext passwords in connection strings and multiple API keys.
assets/sample_codebase/src/user_service.py: Contains a hardcoded PostgreSQL connection string (DATABASE_URL) with a plaintext password and a hardcodedAPI_KEY(sk-1234567890abcdef).assets/sample_codebase/src/payment_processor.py: Contains several hardcoded keys for payment providers, including Stripe (sk_test_EXAMPLE_NOT_REAL), PayPal, and Square.assets/sample_codebase/src/frontend.js: Contains a hardcodedAPI_KEY(abc123def456).- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its core function of processing untrusted external data from codebases and JSON files.
- Ingestion points: Untrusted data enters the agent's context through
debt_scanner.py(which traverses user-provided directories),debt_prioritizer.py(viaload_debt_inventory), anddebt_dashboard.py(viaload_historical_data). - Boundary markers: The skill does not implement delimiters or explicit instructions to the agent to ignore any embedded prompts found within the files it processes.
- Capability inventory: The provided scripts do not contain dangerous capabilities such as
eval(),exec(), orsubprocess.run(), which limits the potential impact of an injection. - Sanitization: No evidence of input validation or sanitization was found to filter out potential prompt injection patterns from the ingested data.
Recommendations
- AI detected serious security threats
Audit Metadata