ponytail-audit
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process the entire repository codebase, creating an attack surface for indirect prompt injection where malicious instructions in the code could influence the agent's behavior.
- Ingestion points: The skill instructions specify scanning the entire codebase and tree (SKILL.md).
- Boundary markers: The skill does not define specific delimiters or instructions to ignore potential commands embedded within the analyzed repository files.
- Capability inventory: The skill is primarily focused on analysis and reporting; it does not explicitly request file-write, network, or code execution capabilities, though it provides a ranked list of suggested deletions (SKILL.md).
- Sanitization: There are no mechanisms described for sanitizing or validating the contents of the files before they are processed by the agent.
Audit Metadata