skills/hgzahn/agentic-coding/i-audit/Gen Agent Trust Hub

i-audit

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external content (code, components, or page designs) provided by the user to perform technical audits.
  • Ingestion points: Untrusted data enters the agent context through the [area] argument and the associated code or design context referenced in the SKILL.md instructions for analysis.
  • Boundary markers: Absent. There are no explicit instructions or delimiters used to isolate the audited content from the agent's core instructions, potentially allowing instructions embedded in the audited code to influence agent behavior.
  • Capability inventory: None. The skill does not have access to subprocesses, file-system writes, or network operations; its output is restricted to generating a text-based diagnostic report.
  • Sanitization: Absent. The skill does not perform escaping or validation of the external content before processing it for the audit report.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 03:50 PM
Security Audit — agent-trust-hub — i-audit