skills/google/mantis/mantis-chain/Gen Agent Trust Hub

mantis-chain

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection]: The skill processes findings and knowledge base entries stored in the workspace. If these artifacts contain content influenced by untrusted target code, they could serve as a vector for indirect prompt injection. This is a known risk for analysis tools and is mitigated here by structured JSON processing.
  • [Workspace Management]: The skill implements complex logic for managing vulnerability findings, including snapshot-based filtering and signature-keyed deduplication. These operations are restricted to the workspace and archive directories, ensuring data integrity across different analysis passes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:43 PM
Security Audit — agent-trust-hub — mantis-chain