pwa-offline-sync

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Surface for indirect prompt injection detected via data ingestion.
  • Ingestion points: The skill reads input from plans/005-adr-offline-sync.md, plans/007-implementation-phases.md, and docs/offline.md to guide implementation and testing.
  • Boundary markers: No explicit delimiters or instructions to ignore potential commands within the documentation files are present.
  • Capability inventory: The skill is configured with Read, Write, Edit, Grep, and Glob tools, allowing it to modify files based on ingested data.
  • Sanitization: The workflow does not include steps to sanitize or validate the content of the project documents before they are used to drive the agent's actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 10:42 AM
Security Audit — agent-trust-hub — pwa-offline-sync