agent-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes local source code and user descriptions, creating an attack surface where malicious instructions in those files could influence the agent's behavior. \n
- Ingestion points:
references/phases/discover/discover.md(scanning the provided code path) andreferences/phases/intake/intake.md(capturing user descriptions). \n - Boundary markers: Present.
references/phases/clarify/clarify.mdcontains explicit instructions to treat collected free-text as data and not follow instructions embedded in it. \n - Capability inventory: The skill can perform file writes, execute local Python scripts via
uv run, and run AWS CLI commands if the user opts into the 'Assisted Build' mode inreferences/phases/poc/poc.md. \n - Sanitization: The skill instructs the agent to treat external content as untrusted text and use structured data formats for internal processing.
Audit Metadata