dbs-report

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill aggregates content from multiple local Markdown archive files to generate summaries and merged reports, which introduces a potential vector for indirect prompt injection.\n
  • Ingestion points: As defined in Step 1 and Step 2 of SKILL.md, the agent reads all .md files located in the session directory {存档根目录}/sessions/{项目名}/.\n
  • Boundary markers: The instructions do not establish clear delimiters or use "ignore instructions" warnings to ensure that the content within the archive files is treated strictly as data rather than as potential instructions for the agent.\n
  • Capability inventory: The skill utilizes file system read and write operations across the project's session and report directories to perform its aggregation and documentation tasks.\n
  • Sanitization: There is no evidence of sanitization or filtering for the content extracted from the archive files, meaning the raw text is processed directly and summarized by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:35 PM
Security Audit — agent-trust-hub — dbs-report