skills/callumflack/skills/code-stacks/Gen Agent Trust Hub

code-stacks

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to "Inspect the live files that will anchor the plan" (SKILL.md), which serves as a primary ingestion point for untrusted data from the repository. The instructions do not define specific boundary markers or delimiters to separate this external content from the agent's core instructions. The capability inventory for this skill includes file system modifications, as seen in the workflow steps to "Patch to add " and "Wire through ". There are no sanitization or validation procedures mentioned for the data read from external files, creating a surface where malicious instructions embedded in the code (e.g., in comments or documentation) could be executed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 11:51 PM