devexpress-xaf-editors

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses specific MCP tools to fetch technical reference material and documentation from the official DevExpress domain (docs.devexpress.com). These downloads are consistent with the vendor's provided functionality and the skill's primary purpose.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks because it ingests data from external URLs into the agent's context during documentation retrieval.
  • Ingestion points: Content retrieved via the devexpress_docs_get_content tool as described in SKILL.md.
  • Boundary markers: The skill contains explicit warnings in SKILL.md instructing the agent to treat fetched text as reference only, to disregard any behavioral directives or commands contained within that text, and to alert the user if such content is encountered.
  • Capability inventory: The skill focuses on code generation guidance and API reference; it does not include scripts for file system modification, persistence, or arbitrary command execution beyond the documentation tools.
  • Sanitization: The skill relies on natural language instructions to guide the agent in filtering and ignoring non-reference content from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 01:47 PM
Security Audit — agent-trust-hub — devexpress-xaf-editors