external-gitcode-ascend-ascend-inference-repos-copilot

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's primary function is technical information retrieval and synthesis. Analysis of the instructions and tool usage patterns reveals no evidence of unauthorized command execution, credential harvesting, or persistence mechanisms. All repository references are consistent with the skill's stated purpose of assisting with the Ascend ecosystem.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface due to its data ingestion capabilities. Ingestion points: Technical documentation is retrieved from external repositories (e.g., vllm-project/vllm, verylucky01/MindIE-LLM) using deepwiki MCP tools. Boundary markers: The prompt instructions do not specify any delimiters or safety guardrails to separate the retrieved data from the core system instructions. Capability inventory: The skill is restricted to information retrieval and text generation, and does not have access to hazardous capabilities such as file system writes, arbitrary shell commands, or network exfiltration tools. Sanitization: No sanitization or verification of the fetched external content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 03:04 AM
Security Audit — agent-trust-hub — external-gitcode-ascend-ascend-inference-repos-copilot