mobile

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of untrusted user task descriptions and the analysis of existing application code during audits.\n
  • Ingestion points: The skill accepts plain-language task descriptions from the user to resolve development modes (in SKILL.md) and reads existing project files during accessibility and store audits (in references/audit.md).\n
  • Boundary markers: There are no specific delimiters or "ignore embedded instructions" warnings defined to separate user-provided content or external file data from the agent's core instructions.\n
  • Capability inventory: The skill utilizes powerful system tools including bash, run_command, write_to_file, replace_file_content, and grep_search (as defined in the agents/openai.yaml configuration).\n
  • Sanitization: The procedure does not include explicit validation, filtering, or escaping of the content ingested from user prompts or project files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:24 PM
Security Audit — agent-trust-hub — mobile