agent-sort
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local repository data to make configuration decisions.
- Ingestion points: The workflow involves reading repository files (e.g., package.json, pyproject.toml) and file listings (rg --files) as defined in the Core Workflow.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded prompts within the analyzed repository data.
- Capability inventory: The skill identifies components for DAILY or LIBRARY buckets, generates an install plan, can create a router skill file in the .claude/skills/ directory, and hands off to other tools like configure-ecc.
- Sanitization: The skill does not perform sanitization of the data read from the repository files before it is processed by the agent.
Audit Metadata