ingest-tool
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it processes untrusted source code to generate new agent instructions.
- Ingestion points: Untrusted source code is read from local files or provided as text input.
- Boundary markers: There are no defined delimiters or instructions to treat the analyzed code as data rather than instructions.
- Capability inventory: The skill has permissions to read and write files, allowing it to persist potentially malicious skill files.
- Sanitization: The skill does not sanitize or validate ingested content before incorporating it into the description, triggers, or YAML frontmatter of the generated SKILL.md.
Audit Metadata