content-hash-cache-pattern

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for processing external files (PDFs, images, text), which creates an entry point for untrusted data that might contain malicious instructions intended for the AI agent.
  • Ingestion points: SKILL.md provides Python snippets that read data from user-specified file paths for hashing and content extraction.
  • Boundary markers: The provided design pattern does not specify delimiters or instructions to ignore embedded commands within the processed file content.
  • Capability inventory: The skill demonstrates file system access (read/write) and SHA-256 hashing capabilities within its architectural examples.
  • Sanitization: While the skill uses standard JSON serialization for cache management, it does not define specific sanitization or filtering logic for the data extracted from the source files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — content-hash-cache-pattern