performance-audit
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing local source code, which serves as an entry point for untrusted data that could contain embedded instructions.
- Ingestion points: Source code files, route definitions, and configuration files (SKILL.md).
- Boundary markers: Not specified in instructions.
- Capability inventory: Read-only file system access.
- Sanitization: No explicit sanitization or escaping of file content before analysis.
- [SAFE]: The skill explicitly defines a 'read-only' operation mode and instructs the agent to avoid fetching production URLs with credentials. References to external repositories and packages (GitHub and NPM) align with the vendor's identity and official ecosystem tools.
Audit Metadata