next-best-thing

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes the entire repository content to determine its actions.\n
  • Ingestion points: Step 1 ('Scan the whole repo') instructs the agent to read structure, entry points, tests, build files, CI configurations, and commit history.\n
  • Boundary markers: The instructions lack delimiters or explicit warnings to the agent to disregard instructions found within the repository files.\n
  • Capability inventory: The skill allows the agent to write files ('Implement the move' in Step 4) and execute shell commands ('Verify and report' in Step 5).\n
  • Sanitization: There is no mechanism to sanitize or validate the content ingested from the repository before it influences the agent's decision-making process.\n- [COMMAND_EXECUTION]: The skill invokes local command-line tools based on the repository's configuration.\n
  • Evidence: Step 5 ('Verify and report') directs the agent to run verification commands such as 'tests, build, lint, type check, or a runtime check'.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 11:43 AM
Security Audit — agent-trust-hub — next-best-thing