image-upload
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructs the agent to retrieve authentication data from the
~/.build-host/credentials.jsonfile to interact with the build.host API. - [PROMPT_INJECTION]: The skill interacts with untrusted data from user repositories, which can lead to indirect prompt injection as it lacks explicit boundary markers or sanitization instructions for that content. * Ingestion points: The project directory and git repository specified in the Required Context (SKILL.md). * Boundary markers: Absent. * Capability inventory: File system edits and interaction with the build.host API for deployment and environment management (SKILL.md). * Sanitization: Not specified.
Audit Metadata