backend

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructs the agent to access sensitive environment configurations and authentication secrets as part of its verification process.\n
  • Evidence: In LITE.md, the agent is directed to "Check .env files or database config module" and "Read environment setup for token secrets" during the GROUND phase.\n- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external project files that could contain malicious instructions.\n
  • Ingestion points: The skill reads configuration files including package.json, go.mod, and .env as seen in LITE.md.\n
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat data from these files as untrusted content.\n
  • Capability inventory: The skill leverages shell execution for commands like npm run build, npx jest, and npm test as described in the DECOMPOSE and EXECUTE sections of LITE.md.\n
  • Sanitization: There is no evidence of validation or sanitization of the content read from external files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:29 AM
Security Audit — agent-trust-hub — backend