tech-stack-evaluator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes unstructured user input and external technology data to generate markdown reports. This creates a surface where malicious instructions embedded in the input (e.g., technology names or descriptions) could influence the agent's behavior when it later processes these reports.
  • Ingestion points: The FormatDetector in scripts/format_detector.py accepts raw input strings from the user for technology analysis.
  • Boundary markers: The system does not utilize explicit delimiters or 'ignore' instructions to isolate interpolated user data within the generated reports.
  • Capability inventory: The ReportGenerator class in scripts/report_generator.py includes functionality to write reports to the local file system using export_to_file.
  • Sanitization: There is no evidence of input validation or sanitization of user-provided strings before they are interpolated into report templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:43 PM
Security Audit — agent-trust-hub — tech-stack-evaluator