production-code-audit

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHPROMPT_INJECTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains multiple instructions designed to bypass user oversight and agent safety constraints.
  • Evidence: Phrases like "Do this automatically without asking the user," "Don't Ask Questions," "Don't Wait for Instructions," and "Automatically scan and understand the entire codebase" explicitly command the agent to ignore standard human-in-the-loop validation steps.
  • [CREDENTIALS_UNSAFE]: The skill mandates the discovery and processing of sensitive credentials.
  • Evidence: Instructions in "Step 2" and the "Production Audit Checklist" explicitly direct the agent to search for "Hardcoded secrets (API keys, passwords in code)" and sensitive files like environment variables across the "entire codebase line-by-line."
  • [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to instructions embedded in the data it processes (source code).
  • Ingestion points: Recursively reads all files in the project directory using listDirectory and readFile (SKILL.md, "Autonomous Scanning Instructions").
  • Boundary markers: Absent. There are no instructions to treat file content as untrusted data or to use delimiters to prevent embedded instructions from influencing agent behavior.
  • Capability inventory: The skill possesses extensive capabilities including reading all files, listing directories, performing string replacements (strReplace), and adding new infrastructure/files.
  • Sanitization: Absent. The agent is instructed to "Understand architecture" and "Fix everything automatically" based directly on the content of the files it reads, which could include malicious payloads.
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to autonomously generate and inject new logic into the project.
  • Evidence: Instructions to "Add production infrastructure" (logging, monitoring, CI/CD pipelines) and "Refactor architecture" result in the agent writing and executing significant code changes without human review.
  • [COMMAND_EXECUTION]: The skill encourages the agent to perform broad, recursive file system operations.
  • Evidence: It requires the agent to "Scan every file in the project recursively" and "Use strReplace to fix issues in files," providing the agent with broad write access to the entire project structure.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — production-code-audit