generate-manifest

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill processes local files to generate metadata, creating a potential surface for indirect prompt injection if project documentation contains instructions intended for the agent. Ingestion points: project files like README.md, AGENTS.md, and source code. Boundary markers: specific instructions define how to infer fields and when to use placeholders. Capability inventory: the skill can write manifest.yaml to the filesystem and execute a local validation command. Sanitization: the process relies on mapping content to a predefined schema.
  • Command Execution: The skill executes a validation command using a local tool. This is a functional requirement to ensure that the generated manifest meets repository standards before being finalized.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:53 AM
Security Audit — agent-trust-hub — generate-manifest