sar-cybersecurity
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data (source code, configuration files, and architecture diagrams) which represents a surface for indirect prompt injection. However, the skill provides strong mitigation via an explicit 'Untrusted input boundary' constraint in
SKILL.md, instructing the agent to never execute or interpret instructions found within the analyzed codebase. - Ingestion points: The skill ingests user-supplied source code,
.envfiles, and CI/CD configurations. - Boundary markers: The skill instructions include a high-priority rule (Constraint 9) to maintain a strict separation between instructions and analyzed content.
- Capability inventory: The skill can read files and perform web searches on official security databases. It is explicitly forbidden from generating executable code or modifying the system.
- Sanitization: The skill generates Markdown reports, reducing the risk of downstream command execution.
- [SAFE]: The skill incorporates multiple defensive constraints, such as a read-only policy outside the output directory, a requirement to release conversation context after completion to prevent data leakage, and a prohibition on installing packages or running shell commands.
- [EXTERNAL_DOWNLOADS]: While the skill uses web search to retrieve CVE information,
SKILL.mdlimits this capability to official security sources (NVD, MITRE, GitHub Advisories) and specifically warns against following arbitrary URLs found in the analyzed codebase.
Audit Metadata