production-code-audit
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains multiple explicit instructions to bypass standard agent safety guardrails and user confirmation loops. It uses directives like "Do this automatically without asking the user", "Don't Ask Questions", and "Don't Wait for Instructions" to enforce autonomous execution of high-risk file modifications.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process entire codebases line-by-line, which makes it highly vulnerable to instructions embedded within the source code it scans.
- Ingestion points: The skill performs a recursive scan of all files in a project using
listDirectoryandreadFile(Step 1). - Boundary markers: No boundary markers or "ignore instructions" delimiters are specified for the scanned content.
- Capability inventory: The agent is granted
strReplacecapabilities to modify files and shell access to execute test suites. - Sanitization: The skill lacks any sanitization or validation logic for the content it ingests from project files.
- [COMMAND_EXECUTION]: The skill instructs the agent to "Run all tests to ensure nothing broke" after modifying the codebase. Because the agent is operating on a potentially untrusted codebase, running the project's test suite involves executing arbitrary code that has not been verified, leading to potential remote code execution (RCE).
Recommendations
- AI detected serious security threats
Audit Metadata