audit-backend-security

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted backend code which represents a potential surface for indirect prompt injection. • Ingestion points: Source code files across multiple directories (e.g., controllers, services, repositories) are read into the agent context for review. • Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore' instructions when reading untrusted code. • Capability inventory: The skill allows the agent to modify code and execute tests based on the audit findings. • Sanitization: No specific sanitization of input code is defined.- [SAFE]: No malicious behavior, unauthorized data access, or suspicious remote dependencies were identified. The documentation provides educational examples of insecure patterns to avoid, such as hardcoded secrets, without containing actual credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 08:36 PM
Security Audit — agent-trust-hub — audit-backend-security