ai-security
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions and reference documentation (references/ai-threat-landscape.md) contain examples of malicious prompt injection strings, such as "Ignore previous instructions" and "You are now a different assistant". These strings are provided strictly for educational purposes and to define detection patterns for the included security tool. They are not attempts to hijack the agent's behavior.
- [INDIRECT_PROMPT_INJECTION]: The
ai_threat_scanner.pyscript is designed to analyze external source code files. While these files represent untrusted input, the tool utilizes static regex-based analysis to identify patterns and generate a structured report. It does not execute the scanned files or interpolate their content into an LLM prompt in a manner that would allow the external data to influence the agent's control flow. - Ingestion points:
scripts/ai_threat_scanner.pyreads content from files at a user-specified path. - Boundary markers: The script processes file content as raw strings for regex matching and does not interpret the content as instructions.
- Capability inventory: The script is restricted to local file reading and console output; it does not perform network operations or code execution based on the scanned data.
- Sanitization: The scanner identifies specific code patterns and returns them as part of a report, rather than using the raw data in generative prompts.
Audit Metadata