vulnerability-validation
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were detected. The skill consists entirely of instructional markdown content for a security analysis workflow.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting external security artifacts, which is a potential surface for indirect prompt injection. However, given the skill's purpose and lack of sensitive capabilities, this is considered a safe architectural pattern. * Ingestion points: Local files in the .bug-hunter/ directory (e.g., findings.json, threat-model.md). * Boundary markers: None specified in the instructions. * Capability inventory: Reading and writing local files related to vulnerability validation. * Sanitization: No explicit sanitization of ingested content is defined.
Audit Metadata