commons-patterns

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructional content and code snippets for using official libraries from the Apache Software Foundation, a trusted open-source organization.
  • [SAFE]: External links point directly to the official Apache Commons documentation and standard placeholder domains like example.com.
  • [SAFE]: Dependency references use official Maven coordinates for well-known, industry-standard libraries such as commons-lang3 and commons-io.
  • [PROMPT_INJECTION]: The skill documents data ingestion via FileUtils.lineIterator and new URL().openStream() in SKILL.md. It lacks explicit boundary markers or delimiters for these external inputs. The capability inventory includes powerful file system operations like forceMkdir and deleteDirectory. No sanitization or validation logic is implemented for the external content processed in the provided examples, creating a surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:24 AM
Security Audit — agent-trust-hub — commons-patterns