production-code-audit

Fail

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions to override standard safety protocols by bypassing user oversight. Directives such as 'Do all of this without asking the user for input,' 'automatically without asking the user,' and 'Don't Ask Questions' encourage the agent to perform destructive or high-risk actions like code refactoring and file modification without a human-in-the-loop.
  • [COMMAND_EXECUTION]: The skill requires the agent to 'Run all tests' autonomously after modifying the codebase. This involves the execution of arbitrary local code which, if the codebase being audited is untrusted, could lead to a compromise of the agent's execution environment.
  • [DATA_EXFILTRATION]: The instructions mandate a recursive, line-by-line scan of all project files, specifically seeking out 'Hardcoded secrets (API keys, passwords in code).' This creates a significant surface for the exposure of sensitive credentials and configuration data.
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection vulnerability surface by processing untrusted data from an entire codebase while possessing file-write and execution capabilities.
  • Ingestion points: The agent is instructed to 'Read all files' and 'Scan every source file' in the project directory using readFile (SKILL.md).
  • Boundary markers: Absent. The skill lacks instructions to isolate processed code from agent instructions or to disregard command-like strings found within the files.
  • Capability inventory: The skill uses strReplace for file modification and is instructed to 'Run all tests,' which allows for shell command execution.
  • Sanitization: Absent. There is no evidence of filtering or sanitizing the content read from the files before it is processed by the agent's logic.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — production-code-audit