find-breaking-rest-api

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill requires the agent to ingest and analyze potentially untrusted project data (source code, git history, commit messages) which could contain malicious instructions designed to manipulate the agent's behavior.
  • Ingestion points: The skill uses Read, Grep, and Glob tools to retrieve content from various project files including controllers, routers, schemas, and security configurations.
  • Boundary markers: The instructions do not define any delimiters or markers to help the agent distinguish between its instructions and the analyzed data, nor do they specify to ignore embedded instructions in the files.
  • Capability inventory: The agent has access to Bash and PowerShell tools, providing a broad execution capability if a prompt injection is successfully triggered via malicious file content.
  • Sanitization: No mechanism for sanitizing or filtering the content of the analyzed files is mentioned in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:23 AM
Security Audit — agent-trust-hub — find-breaking-rest-api