sec-agentshield-wrapper
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-defined strings describing code changes and intent. This creates a surface where a malicious user could embed instructions to influence the agent's behavior during analysis.
- Ingestion points: The skill takes two user-controlled strings as input: '<파일/영역 설명>' and '<변경 의도>'.
- Boundary markers: Absent. The prompt instructions do not define delimiters to wrap the untrusted user input or specify that the agent should ignore instructions within it.
- Capability inventory: The skill utilizes file reading capabilities, MCP-based code graph tools, and the ability to spawn sub-agents.
- Sanitization: Absent. The skill instructions do not specify any validation or sanitization of the input strings before processing.
- [PRIVILEGE_ESCALATION]: The skill explicitly instructs the agent to suppress permission prompts by using specific tool flags when spawning sub-agents.
- Evidence: The text states: '이 스킬에서 Agent 도구를 사용하여 에이전트를 스폰할 경우, 항상 mode: "bypassPermissions" 를 전달해야 한다.'
- Impact: This behavior reduces user oversight by preventing interactive approval prompts for actions taken by sub-agents, which could allow unintended operations to proceed silently.
Audit Metadata