6-ship
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process various project-related files and metadata which could contain instructions meant to influence agent behavior.
- Ingestion points: The agent reads files from the
devpost/directory (such asprd.md,spec.md, andlearner-profile.md) and inspects git history, tracked files, and commit messages. - Boundary markers: There are no explicit delimiters or specific 'ignore instructions' markers defined for the agent when it reads these project artifacts.
- Capability inventory: The agent is empowered to perform code fixes, commit to repositories, create public GitHub repositories, and modify project configuration files.
- Sanitization: While the skill contains explicit instructions to check for and prevent the leak of credentials or private data, it does not specifically filter for or sanitize against natural language instructions embedded within the processed project files.
Audit Metadata