deepinit
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read and follow instructions from the local file
.agents/workflows/deepinit.md.\n - Ingestion points: The file
.agents/workflows/deepinit.mdis loaded into the agent's context as the primary source of operational instructions.\n - Boundary markers: The instructions do not include delimiters or specific guidance to the agent to treat the workflow file as untrusted data or to ignore potentially malicious embedded instructions.\n
- Capability inventory: The skill description indicates the capability to generate files (
AGENTS.md,ARCHITECTURE.md) and create directory structures (docs/), implying write permissions to the file system.\n - Sanitization: There is no evidence of content validation or sanitization before the agent executes the steps defined in the workflow file.
Audit Metadata