scout
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data which serves as a potential vector for indirect prompt injection.
- Ingestion points: The skill is instructed to read
plan.md, artifacts, and arbitrary files discovered during codebase exploration in theSKILL.mdworkflow. - Boundary markers: The instructions lack explicit delimiters or directions for the agent to ignore instructions embedded within the files it reads.
- Capability inventory: The skill has the ability to join workspace sessions using the
run_workspacetool and write content to artifacts via thewrite_artifacttool. - Sanitization: There is no mention of sanitizing or validating the content read from files before it is processed or written into the final report.
Audit Metadata