artifact-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from local files provided via user-defined or auto-discovered paths. There is a risk that these documents could contain malicious instructions (indirect prompt injection) designed to override the agent's intent or bias the resulting analysis report.
- Ingestion points: Content is read from local filesystem paths specified in the
pathsargument or discovered in conventional project locations (e.g.,docs/,.beagle/concepts/). - Boundary markers: While the skill uses a structured citation schema, it does not explicitly define delimiters or instructions to ignore embedded prompts within the source documents provided to subagents.
- Capability inventory: The skill utilizes filesystem read and write capabilities to generate plans, findings, and reports. It does not perform network operations.
- Sanitization: The instructions do not specify sanitization or filtering of the document content before it is processed by the language model.
- [CREDENTIALS_UNSAFE]: The skill includes a robust security control in
references/skip-patterns.mdwhich defines a non-overridable denylist for sensitive file types and directories. This effectively prevents the skill from reading secrets, including.envfiles, SSH keys, AWS credentials, and private keys, even if they are explicitly targeted in the input paths.
Audit Metadata