planning
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions in
references/codebase-understanding.mddirect the agent to "Analyze dotenv files and configuration." Reading.envfiles is a high-risk activity as they often contain sensitive secrets, API keys, and credentials. - [EXTERNAL_DOWNLOADS]: The
references/research-phase.mdfile instructs the agent to use therepomix --remotecommand to fetch and summarize content from external GitHub repositories, which involves downloading data from untrusted sources into the agent's context. - [COMMAND_EXECUTION]: The skill requires the use of shell-based tools, including
ghfor GitHub metadata analysis andrepomixfor repository summarization, as specified inreferences/research-phase.md. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and process data from external GitHub repositories and local codebase files without implementing security boundaries or sanitization.
- Ingestion points: Environment configuration files (
.env), local codebase files, and remote GitHub repositories fetched viarepomix(identified inreferences/codebase-understanding.mdandreferences/research-phase.md). - Boundary markers: Absent. The instructions do not define delimiters or provide guidance to ignore embedded instructions within the processed data.
- Capability inventory: The agent can execute shell commands (
gh,repomix), write multiple plan and report files to the filesystem, and spawn specialized sub-agents (scout,researcher,debugger). - Sanitization: Absent. There are no instructions for the agent to sanitize or escape content from external files or repositories before interpretation.
Audit Metadata