project-guidelines-example

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The example code for Claude AI integration demonstrates a vulnerability where untrusted data could influence agent behavior.
  • Ingestion points: The analyze_with_claude function in SKILL.md accepts a content string from an unspecified external source.
  • Boundary markers: The example code lacks any delimiters or specific instructions (e.g., system prompts or XML tags) to help the model distinguish between instructions and the data being analyzed.
  • Capability inventory: The model is granted tool-calling capabilities (provide_analysis) which could be misused if the content contains malicious instructions.
  • Sanitization: There is no evidence of input validation or sanitization before the data is passed to the AI model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — project-guidelines-example