skills/google/capsem/ironbank/Gen Agent Trust Hub

ironbank

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Command Execution]: The skill utilizes standard system tools and package managers, including just, apt, npm, pip, uv, and docker, to build artifacts and run acceptance tests. These operations involve executing shell commands, which is expected behavior for a release and security acceptance framework.
  • [Indirect Prompt Injection Surface]: The skill verifies system behavior by ingesting data from multiple sources, such as CLI help text, route responses, database rows, and structured logs. This creates a surface where external data enters the agent's context, though it is used for automated verification within a testing discipline.
  • Ingestion points: CLI help, documentation, route responses, generated schemas, logs, database rows, and package metadata.
  • Boundary markers: The skill does not explicitly define delimiters for these specific inputs within the instructions.
  • Capability inventory: The skill involves shell command execution (just), package manager operations (apt, npm, pip, uv), and container management (Docker).
  • Sanitization: No specific sanitization or validation routines are described for the processed data inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:45 PM
Security Audit — agent-trust-hub — ironbank