domain-organization
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from source code repositories, including instructions, manifests, and documentation.
- Ingestion points: Target repository instructions, manifests (e.g., package.json, import maps), and source files are ingested from the working tree as described in SKILL.md.
- Boundary markers: The instructions explicitly direct the agent to distinguish verified facts from proposed paths and reconcile evidence with the actual working tree in SKILL.md.
- Capability inventory: The skill manages file moves, import updates, and build root modifications across the repository as detailed in SKILL.md.
- Sanitization: No explicit sanitization or filtering of ingested instruction content is defined.
- [EXTERNAL_DOWNLOADS]: The skill references specific integration points with external tooling packages in references/enforcement.md.
- Evidence: References to @darkmatter/oxlint/organization and @darkmatter/dependency-cruiser.
- Context: These packages are vendor-owned resources belonging to the skill author 'darkmatter'. The skill includes instructions that prohibit the agent from performing unauthorized installations or dependency upgrades.
Audit Metadata