maven-multi-branch-license-gate-hardening

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including build logs, license reports, and repository configuration files. This creates a potential surface where malicious instructions embedded in project metadata could attempt to influence the agent's behavior. * Ingestion points: The skill reads project instructions, command logs, report paths, and repository metadata as defined in SKILL.md and references/evidence-contract.md. * Boundary markers: There are no explicit boundary markers or instructions to treat external data as untrusted prose within the skill definition. * Capability inventory: The skill is authorized to interact with Maven toolchains, Git repositories, and file system paths for auditing purposes. * Sanitization: The skill contains robust mitigation strategies in references/anti-patterns.md, specifically instructing the agent to strip tokens, authorization headers, and repository credentials from logs before sharing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:49 AM
Security Audit — agent-trust-hub — maven-multi-branch-license-gate-hardening