tinystruct-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation and implementation patterns for the tinystruct Java framework. The provided code examples, configuration samples, and CLI references (e.g., bin/dispatcher) are consistent with the framework's stated purpose and do not contain malicious code or exfiltration patterns.
- [PROMPT_INJECTION]: The skill includes a dedicated security section warning developers about prompt injection risks when building Model Context Protocol (MCP) tools. It provides specific instructions and code examples for validating and sanitizing inputs, demonstrating proactive security guidance for developers.
- [CREDENTIALS_UNSAFE]: The documentation includes a sample application.properties file with database configuration. The credentials provided (user=sa, password=) are standard default values for development databases and serve as safe placeholders for documentation purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill documents the processing of external input through framework actions.
- Ingestion points: Tool arguments defined in MCPTool extensions (SKILL.md) and @Action method parameters (references/routing.md).
- Boundary markers: The documentation includes security warnings and explicit instructions to validate and sanitize caller-supplied arguments.
- Capability inventory: The framework provides outbound HTTP networking (references/system-usage.md) and database persistence (references/database.md).
- Sanitization: The skill provides code examples implementing input sanitization using regular expressions and length checks (SKILL.md).
Audit Metadata