lit-components
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes a
review: neverinstruction in its frontmatter. This is a directive intended to override standard human-in-the-loop review processes, thereby reducing oversight of the agent's modifications to the codebase.\n- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to execute build and test scripts within a repository, creating a vulnerability surface where a compromised repository could execute malicious code during these phases.\n - Ingestion points: Source code and build configurations from the repository being modified (SKILL.md).\n
- Boundary markers: Absent; the instructions do not specify any validation or isolation for the repository's scripts.\n
- Capability inventory: Execution of arbitrary shell commands via compile, lint, and test scripts (SKILL.md).\n
- Sanitization: Absent; the skill does not recommend checking the integrity of the environment or scripts before execution.
Audit Metadata