tech-debt-tracker

Fail

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded credentials and secrets were identified within the sample codebase files provided in the skill's assets. This includes plaintext passwords in connection strings and multiple API keys.
  • assets/sample_codebase/src/user_service.py: Contains a hardcoded PostgreSQL connection string (DATABASE_URL) with a plaintext password and a hardcoded API_KEY (sk-1234567890abcdef).
  • assets/sample_codebase/src/payment_processor.py: Contains several hardcoded keys for payment providers, including Stripe (sk_test_EXAMPLE_NOT_REAL), PayPal, and Square.
  • assets/sample_codebase/src/frontend.js: Contains a hardcoded API_KEY (abc123def456).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its core function of processing untrusted external data from codebases and JSON files.
  • Ingestion points: Untrusted data enters the agent's context through debt_scanner.py (which traverses user-provided directories), debt_prioritizer.py (via load_debt_inventory), and debt_dashboard.py (via load_historical_data).
  • Boundary markers: The skill does not implement delimiters or explicit instructions to the agent to ignore any embedded prompts found within the files it processes.
  • Capability inventory: The provided scripts do not contain dangerous capabilities such as eval(), exec(), or subprocess.run(), which limits the potential impact of an injection.
  • Sanitization: No evidence of input validation or sanitization was found to filter out potential prompt injection patterns from the ingested data.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 4, 2026, 01:33 PM