updateagents
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the workspace and incorporates it into authoritative agent instructions.
- Ingestion points:
scripts/updateagents.ts(lines 142, 160, 220) readspackage.json,composer.json, and existing agent files likeAGENTS.mdorCLAUDE.md. - Boundary markers: Content is merged in
mergeIntoContextFile(lines 280-312) without explicit markers advising the agent to ignore embedded instructions. - Capability inventory: The skill utilizes
bash,view_file, andwrite_to_filetools as defined inSKILL.md. - Sanitization: Ingested content is not sanitized or validated before being written to context files.
- [COMMAND_EXECUTION]: The
references/discovery-commands.mdfile contains a variety of shell commands for the agent to execute for workspace analysis. These commands involve scanning the file system and extracting data from various file types using tools likerg,fd, andjq.
Audit Metadata