ai-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses directive language such as "Use PROACTIVELY for LLM features..." in the frontmatter and description to influence the agent's prioritization and decision-making logic.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to build systems that ingest and process external, potentially untrusted data (e.g., product documentation for RAG). The provided implementation examples lack explicit sanitization or filtering of retrieved content before it is interpolated into LLM prompts, creating a vulnerability surface for instructions embedded in source documents to influence the agent's behavior at runtime. This risk is combined with access to high-capability tools like
BashandWebFetch.
Audit Metadata