improve
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external project data, including source code, UI layouts, and application flows. This provides a potential attack surface where malicious instructions embedded in a project's files or metadata could influence the agent's behavior during the audit process.
- Ingestion points: The skill instructs the agent to read source files, screenshots, and call paths from the user's environment.
- Boundary markers: There are no explicit instructions to treat the analyzed content as untrusted data or use specific delimiters to separate code from instructions.
- Capability inventory: The agent has the ability to write to the filesystem and execute shell commands for testing.
- Sanitization: The instructions do not specify a process for sanitizing or escaping the content being audited.
- [DYNAMIC_EXECUTION]: When used in 'Execute' mode, the skill creates code modifications and immediately executes the updated code or its test suite to verify the changes. This represents the generation and execution of scripts at runtime.
- Evidence: The 'Process' section specifies that the agent should 'apply the fixes immediately' and 'Verify after: render the UI, walk the flow, run the code and tests.'
Audit Metadata