tech-stack-evaluator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes unstructured user input and external technology data to generate markdown reports. This creates a surface where malicious instructions embedded in the input (e.g., technology names or descriptions) could influence the agent's behavior when it later processes these reports.
- Ingestion points: The
FormatDetectorinscripts/format_detector.pyaccepts raw input strings from the user for technology analysis. - Boundary markers: The system does not utilize explicit delimiters or 'ignore' instructions to isolate interpolated user data within the generated reports.
- Capability inventory: The
ReportGeneratorclass inscripts/report_generator.pyincludes functionality to write reports to the local file system usingexport_to_file. - Sanitization: There is no evidence of input validation or sanitization of user-provided strings before they are interpolated into report templates.
Audit Metadata