vulnerability-validation
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from security findings which could theoretically contain malicious instructions designed to influence the agent's validation process.\n
- Ingestion points: The skill reads
security-findings.jsonand.factory/threat-model.mdto establish context (SKILL.md).\n - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded prompts within the findings data.\n
- Capability inventory: The skill has file system access for reading and writing JSON results, and instructions describe verification steps using shell commands like
jq(SKILL.md).\n - Sanitization: No explicit sanitization or filtering of the input finding content is implemented beyond verifying that the output is valid JSON.
Audit Metadata