agent-architecture-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code from a provided
codebase_pathto perform a compliance audit.\n- Ingestion points: The skill ingests file content from thecodebase_pathparameter usinggrepcommands and targeted file reads as defined in the Analysis Workflow andreferences/factors.md.\n- Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" wrappers when processing the codebase files, which is a common vulnerability surface.\n- Capability inventory: The skill usesgrepfor discovery and deep-dive file reads to gather evidence for generating its report.\n- Sanitization: No sanitization or escaping of the ingested code content is specified before it is processed by the agent, increasing the risk of the agent obeying instructions hidden in the code it audits.
Audit Metadata