ghost-scan-code
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of repository source code during the analysis phase.
- Ingestion points: The
Analyzer Agent(prompts/analyzer.md) reads candidate files from the target repository to find vulnerabilities. - Boundary markers: The skill does not explicitly use boundary markers or delimiters when presenting the untrusted code content to the agent for analysis, nor does it provide instructions to ignore instructions embedded within the scanned code.
- Capability inventory: The skill has access to sensitive tools including
Read,Write,Edit, andBash, which could be abused if an injection is successful. - Sanitization: There is no evidence of sanitization or filtering of the source code content before it is interpolated into the agent's prompt context.
Audit Metadata