integration-contract

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes data from external, potentially untrusted sources to drive automated actions.
  • Ingestion points: During the build mode, the skill reads external specifications (PRDs), sub-issues, and performs searches (rg/git grep) across repository source code to identify API surfaces and consumer call-sites.
  • Boundary markers: The instructions do not provide explicit boundary markers or instructions for the agent to ignore potentially malicious embedded commands within the specifications or code it retrieves.
  • Capability inventory: The skill has a high-privilege capability set, including writing files to the local workspace (contract.md), dispatching local sub-agents for concurrent work, and executing automated browser flows (agent-browser) or CLI assertions (curl) during the gate phase.
  • Sanitization: There is no mention of sanitizing, escaping, or validating the content retrieved from PRDs or code before it is used to generate the smoke checklist or executed as part of the integration gate.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 06:25 PM
Security Audit — agent-trust-hub — integration-contract