Auditing Security

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit external codebases, which are untrusted ingestion points that could contain malicious instructions.\n
  • Ingestion points: External codebase to audit, docs/system-design.md, docs/api-contracts.yaml, and feature implementation markdown files specified in SKILL.md.\n
  • Boundary markers: The instructions lack explicit boundary markers or directions for the agent to ignore potentially malicious embedded prompts within the files being audited.\n
  • Capability inventory: The skill involves the analysis of code and mentions using audit tools like npm audit, although no specific tool permissions are granted in the frontmatter.\n
  • Sanitization: There is no evidence of sanitization or input validation for the data ingested during the audit process.\n- [NO_CODE]: The skill is purely instructional markdown and does not distribute any executable scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:21 PM
Security Audit — agent-trust-hub — Auditing Security