agents-md-edit
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent on how to manage and edit AGENTS.md, which acts as a source of instructions for the agent. Untrusted content within this file could lead to indirect prompt injection.
- Ingestion points: The skill refers to reading and merging content from AGENTS.md using the smartMergeAgentsMd process.
- Boundary markers: The workflow relies on specific comment tags (e.g., and ) which could be manipulated or spoofed by malicious content.
- Capability inventory: The agent is tasked with editing and potentially committing changes to the repository's instructional files (AGENTS.md).
- Sanitization: There are no instructions for the agent to sanitize, validate, or ignore instructions embedded within the content it is merging or editing.
Audit Metadata