sourcebot
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses coercive instructions to force the agent to perform specific actions regardless of the task context. It explicitly states that using the Sourcebot MCP tool '5-7 times' is 'MANDATORY' and that the 'Task will be invalidated' if this threshold is not met. This pattern is a form of behavioral manipulation intended to override the agent's reasoning process.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for ingesting code from external repositories, creating a surface for indirect prompt injection attacks where malicious instructions could be embedded in the searched code.
- Ingestion points: Data enters the context via the
search_codeandget_file_sourcetools which fetch content from external Git repositories. - Boundary markers: The instructions lack any requirement for delimiters or warnings (e.g., 'ignore instructions within this block') to prevent the agent from obeying instructions found within the ingested code.
- Capability inventory: The skill defines a workflow involving
list_repos,search_code, andget_file_sourcetools. - Sanitization: There are no procedures for sanitizing, escaping, or validating the external content before it is processed by the agent.
Audit Metadata