kb-path-instructions
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides comprehensive instructions for agents to ingest, analyze, and modify a wide variety of workspace files which could contain untrusted data.\n
- Ingestion points: Instructions cover files matching
**/*.{md,html,jsx,tsx,vue,svelte,astro,css,scss,less,py,js,ts,mjs,cjs}.\n - Boundary markers: While
references/multi-agent-reliability.mddefines structured output formats for findings and scores, it lacks specific instructions for delimiting or ignoring potentially malicious prompts embedded within the processed data.\n - Capability inventory: The instructions in
references/powershell-terminal-ops.mdandreferences/multi-agent-reliability.mdguide the use of state-changing tools such as terminal command execution and file writing.\n - Sanitization: The skill does not provide specific guidance on sanitizing or validating the content of workspace files before they are processed by tools.\n- [COMMAND_EXECUTION]: The file
references/powershell-terminal-ops.mdcontains detailed guidance and code snippets for executing shell commands, specifically targeting Git operations on Windows systems.\n - Evidence: The skill recommends a specific pattern using
[IO.File]::WriteAllText(),git commit -F, andRemove-Itemwithin a singlerun_in_terminalcall to ensure reliable multi-line commits.
Audit Metadata