launch-readiness-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external codebase data, creating a potential surface for indirect prompt injection.
  • Ingestion points: The agent ingests project codebase content using Read, Glob, and Grep tools during the discovery and analysis phases defined in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore instructions' directives for the content read from the files.
  • Capability inventory: The skill allows the use of Bash for command execution (e.g., running tests) and WebFetch for network access, which could be targeted by instructions hidden in the analyzed data.
  • Sanitization: No explicit sanitization or validation of the ingested code content is mentioned before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — launch-readiness-auditor