backend
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructs the agent to access sensitive environment configurations and authentication secrets as part of its verification process.\n
- Evidence: In
LITE.md, the agent is directed to "Check .env files or database config module" and "Read environment setup for token secrets" during the GROUND phase.\n- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external project files that could contain malicious instructions.\n - Ingestion points: The skill reads configuration files including
package.json,go.mod, and.envas seen inLITE.md.\n - Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat data from these files as untrusted content.\n
- Capability inventory: The skill leverages shell execution for commands like
npm run build,npx jest, andnpm testas described in the DECOMPOSE and EXECUTE sections ofLITE.md.\n - Sanitization: There is no evidence of validation or sanitization of the content read from external files before it is processed by the agent.
Audit Metadata