sandbox-unblock

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured troubleshooting steps for diagnosing sandbox blockers, focusing on technical verification of environment variables, exit codes, and path resolution. No malicious code or exfiltration patterns were identified.
  • [PROMPT_INJECTION]: The skill advises the agent to verify sandbox behavior through direct measurement rather than relying on the system prompt's description. While this uses language that overrides system context, it is used here to explain the technical distinction between tool-specific permissions (e.g., the Read tool) and general Bash capabilities.
  • [PROMPT_INJECTION]: The skill defines a reporting workflow that ingests untrusted data from command failures and error messages, which represents a surface for indirect prompt injection.
  • Ingestion points: The 'Report template' in SKILL.md includes fields for 'Exact command typed' and 'Raw error received'.
  • Boundary markers: The template uses literal placeholders (e.g., ) to delimit external data.
  • Capability inventory: The skill employs Bash, Read, and Grep tools for diagnostics.
  • Sanitization: No explicit sanitization or filtering logic is described for the ingested error strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:36 AM
Security Audit — agent-trust-hub — sandbox-unblock