agent-watchdog

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from external sources, including agent transcripts, PR descriptions, and chat logs (SKILL.md). While this creates an attack surface for indirect prompt injection, the instructions include guidance to treat the original user request as the source of truth rather than the audited agent's claims.
  • Ingestion points: Session IDs, transcripts, thread URLs, PRs, branches, and logs (SKILL.md).
  • Boundary markers: The skill does not explicitly define markers (such as XML tags or specific delimiters) to isolate untrusted agent output from the primary instructions.
  • Capability inventory: The skill can read local files, check git diffs, and execute validation commands or tests to verify agent work (SKILL.md).
  • Sanitization: No specific filtering or sanitization of external transcripts is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:04 AM
Security Audit — agent-trust-hub — agent-watchdog