coverage
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of reading and analyzing untrusted data from the filesystem.
- Ingestion points: The skill reads route definitions, component logic, and existing test files (*.spec.ts, *.spec.js) located in the project repository.
- Boundary markers: No specific boundary markers or instructions are provided to the agent to treat the content of these files as untrusted data or to ignore instructions embedded within them.
- Capability inventory: The skill utilizes Glob, Grep, and Read tools for data retrieval and mentions invoking /pw:generate to create new files based on analysis results.
- Sanitization: There is no evidence of sanitization or validation of the ingested code content before it is processed.
Audit Metadata