ingest-tool

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it processes untrusted source code to generate new agent instructions.
  • Ingestion points: Untrusted source code is read from local files or provided as text input.
  • Boundary markers: There are no defined delimiters or instructions to treat the analyzed code as data rather than instructions.
  • Capability inventory: The skill has permissions to read and write files, allowing it to persist potentially malicious skill files.
  • Sanitization: The skill does not sanitize or validate ingested content before incorporating it into the description, triggers, or YAML frontmatter of the generated SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:42 AM
Security Audit — agent-trust-hub — ingest-tool