security-threat-model

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted repository content and project summaries to build its threat model, providing an ingestion point for indirect prompt injection. A malicious codebase could contain instructions within comments or files designed to manipulate the agent's behavior or findings. The skill is capable of writing the resulting report to the local filesystem. Mitigations include requirements for architectural claims to be anchored to repository evidence and explicit redaction rules.
  • [CREDENTIALS_UNSAFE]: The skill instructions direct the agent to search for sensitive file paths and security-critical assets including hardcoded secrets, API keys, and environment variables. Although this is a core function for a security audit tool, it represents intentional access to sensitive information. The skill includes a clear safety instruction in its system prompt to redact all secrets from the final output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:48 PM
Security Audit — agent-trust-hub — security-threat-model