nextreme-decision
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and analyze data from the repository (code, structure, tests, and history) which constitutes untrusted external input that could contain malicious instructions designed to influence the agent's decision-making logic.
- Ingestion points: Repository files, structure, and history are scanned during the 'Scan the repo for evidence' phase.
- Boundary markers: The instructions lack explicit delimiters or warnings for the agent to ignore potential instructions embedded within the repository content being analyzed.
- Capability inventory: The skill focuses on file reading and reasoning to produce a verdict; it does not include instructions for file writing, network operations, or command execution within the provided workflow.
- Sanitization: There are no instructions provided for sanitizing, escaping, or filtering external repository content before it is processed by the agent.
Audit Metadata