00-andruia-consultant
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted local data by scanning workspace files (e.g.,
package.json, source code) during its technical diagnostic phase. This creates a surface for indirect prompt injection, where malicious instructions hidden in a project's files could influence the agent's behavior. - Ingestion points: Technical scanning of the workspace (src, package.json, etc.) in the 'Escenario B: Proyecto Existente' workflow.
- Boundary markers: The instructions lack specific delimiters or guidelines for the agent to ignore instructions found within analyzed data.
- Capability inventory: The skill is configured to use developer tools (e.g.,
claude-code,codex-cli) and performs file-writing operations to generate technical artifacts liketareas.md. - Sanitization: No explicit sanitization or content validation steps are defined for the ingested files before they are processed by the agent.
Audit Metadata