updateagents

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the workspace and incorporates it into authoritative agent instructions.
  • Ingestion points: scripts/updateagents.ts (lines 142, 160, 220) reads package.json, composer.json, and existing agent files like AGENTS.md or CLAUDE.md.
  • Boundary markers: Content is merged in mergeIntoContextFile (lines 280-312) without explicit markers advising the agent to ignore embedded instructions.
  • Capability inventory: The skill utilizes bash, view_file, and write_to_file tools as defined in SKILL.md.
  • Sanitization: Ingested content is not sanitized or validated before being written to context files.
  • [COMMAND_EXECUTION]: The references/discovery-commands.md file contains a variety of shell commands for the agent to execute for workspace analysis. These commands involve scanning the file system and extracting data from various file types using tools like rg, fd, and jq.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — updateagents