backend-scan

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection.
  • Ingestion points: Reads arbitrary project source code, configuration manifests (e.g., package.json, requirements.txt), and internal memory files in .opencode/everything-backend-memory/.
  • Boundary markers: Lacks specific markers or instructions to the agent to disregard instructions found within the scanned files, increasing the risk of the agent obeying commands embedded in comments or metadata.
  • Capability inventory: Authorized to read/write project files and communicate findings to the user.
  • Sanitization: No content filtering or validation is applied to the data ingested from the project files.
  • [COMMAND_EXECUTION]: Executes system commands for analysis.
  • The skill uses git to retrieve commit timestamps for staleness detection and change tracking. This is consistent with its stated purpose of project synchronization and drift detection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 10:46 AM
Security Audit — agent-trust-hub — backend-scan