docslime-fill

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and executing instructions embedded within <!-- LLM: ... --> comments located in files under the docs/ directory. This creates an attack surface where a compromised or malicious template could influence the agent's behavior.
  • Ingestion points: The agent is instructed to open and read target files (e.g., docs/PRODUCT.md) to extract guidance comments.
  • Boundary markers: While the agent looks for specific <!-- LLM: ... --> tags, the instructions do not include specific safeguards against adversarial content within those tags.
  • Capability inventory: The skill possesses the ability to read and write files within the local project structure and execute shell commands such as grep for verification.
  • Sanitization: The process relies on a human-in-the-loop interview format, but there is no explicit sanitization of the embedded template instructions before the agent interprets them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:33 PM
Security Audit — agent-trust-hub — docslime-fill