work-with-common-project-structure
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill describes and encourages the use of specific commands,
scbuildcodeunitandscbuildcodeunitsc, to execute build and linting scripts directly on the host machine or within a containerized environment. - [EXTERNAL_DOWNLOADS]: The skill references a remote markdown file located at
https://projects.aniondev.de/PublicProjects/Common/ProjectTemplates/-/raw/main/Conventions/RepositoryStructure/CommonProjectStructure/CommonProjectStructure.md. This is a resource belonging to the author's infrastructure used to provide project conventions. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by instructing the agent to ingest and follow instructions from an external data source.
- Ingestion points: The agent is directed to read content from a remote URL on
projects.aniondev.deas defined inSKILL.md. - Boundary markers: None. There are no instructions to the agent to distinguish between the provided data and instructions within the fetched content.
- Capability inventory: The skill identifies capabilities for executing local shell commands (
scbuildcodeunit). - Sanitization: None. The skill does not specify any validation or filtering for the external content before it is processed by the agent.
Audit Metadata