start-routing-data
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a mandatory workflow where the agent ingests and processes data from the local codebase, which is a potential surface for indirect prompt injection.\n
- Ingestion points: The agent is instructed to explore project source files including
src/routes/, loaders, androuter.tsxto map the application structure (Workflow step 1).\n - Boundary markers: Absent. The instructions do not specify delimiters or guidelines to distinguish code from potential malicious instructions within the project files.\n
- Capability inventory: The agent workflow utilizes
fuse-ai-pilottools for codebase exploration and targeted code modifications.\n - Sanitization: Absent. The skill does not provide instructions for sanitizing or validating content retrieved from the file system before it is used for logic or code generation.\n- [SAFE]: The skill uses external tools and documentation from recognized sources.\n
- The mandatory workflow utilizes
fuse-ai-pilottools, which are vendor resources associated with the skill author.\n - Documentation references link to
tanstack.com, a well-known service in the React community.
Audit Metadata