threat-detection

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (log files) which presents a surface for indirect prompt injection attacks.
  • Ingestion points: The scripts/threat_signal_analyzer.py script reads arbitrary log files provided via the --file parameter.
  • Boundary markers: The script outputs results in a structured text or JSON format, but does not wrap extracted log snippets in clear delimiters or include 'ignore embedded instructions' warnings for the downstream agent.
  • Capability inventory: The skill is capable of reading file system contents and printing them to standard output. It does not perform network operations or persistent changes.
  • Sanitization: The script truncates evidence to 200 characters but lacks sanitization or escaping of the actual content extracted from the logs, meaning payloads targeting the LLM's instructions could be passed through to the agent's context.- [METADATA_POISONING]: An inconsistency exists in metadata where the author is listed as 'borghei' in the SKILL.md frontmatter, but the scripts/threat_signal_analyzer.py file attributes the code to the 'Claude Skills Engineering Team'. This suggests deceptive or poorly maintained metadata, though it does not indicate malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:20 AM
Security Audit — agent-trust-hub — threat-detection