content-hash-cache-pattern
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for processing external files (PDFs, images, text), which creates an entry point for untrusted data that might contain malicious instructions intended for the AI agent.
- Ingestion points:
SKILL.mdprovides Python snippets that read data from user-specified file paths for hashing and content extraction. - Boundary markers: The provided design pattern does not specify delimiters or instructions to ignore embedded commands within the processed file content.
- Capability inventory: The skill demonstrates file system access (read/write) and SHA-256 hashing capabilities within its architectural examples.
- Sanitization: While the skill uses standard JSON serialization for cache management, it does not define specific sanitization or filtering logic for the data extracted from the source files.
Audit Metadata