production-code-audit

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains multiple explicit instructions to bypass standard agent safety guardrails and user confirmation loops. It uses directives like "Do this automatically without asking the user", "Don't Ask Questions", and "Don't Wait for Instructions" to enforce autonomous execution of high-risk file modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process entire codebases line-by-line, which makes it highly vulnerable to instructions embedded within the source code it scans.
  • Ingestion points: The skill performs a recursive scan of all files in a project using listDirectory and readFile (Step 1).
  • Boundary markers: No boundary markers or "ignore instructions" delimiters are specified for the scanned content.
  • Capability inventory: The agent is granted strReplace capabilities to modify files and shell access to execute test suites.
  • Sanitization: The skill lacks any sanitization or validation logic for the content it ingests from project files.
  • [COMMAND_EXECUTION]: The skill instructs the agent to "Run all tests to ensure nothing broke" after modifying the codebase. Because the agent is operating on a potentially untrusted codebase, running the project's test suite involves executing arbitrary code that has not been verified, leading to potential remote code execution (RCE).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — production-code-audit