discover-entry-points

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs legitimate analysis of local source code to identify security entry points (Spring, JAX-RS, etc.) and project dependencies. No malicious patterns or unauthorized behaviors were detected.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it reads and processes external source code and configuration files. 1. Ingestion points: Project source code files and build descriptors (e.g., pom.xml, build.gradle). 2. Boundary markers: No specific delimiters or instructions are used to separate analysis instructions from code content. 3. Capability inventory: File system read access to the project directory; write access to the opentaint-analysis-plan.md file. 4. Sanitization: Content read from files is used to populate documentation and does not appear to be sanitized for potential embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 10:25 AM
Security Audit — agent-trust-hub — discover-entry-points