source-driven-development

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local configuration files to determine the technology stack, which informs subsequent web fetching actions. This introduces a potential surface for indirect prompt injection if an attacker can manipulate a repository's dependency files to misdirect the agent's implementation logic.\n
  • Ingestion points: Ingests stack data from package.json, composer.json, requirements.txt, pyproject.toml, go.mod, Cargo.toml, and Gemfile (SKILL.md).\n
  • Boundary markers: No specific boundary markers are defined for the parsing of dependency files.\n
  • Capability inventory: The skill utilizes web-fetching capabilities to retrieve documentation from external domains.\n
  • Sanitization: The skill mitigates risks by defining a strict hierarchy of authoritative sources (e.g., official docs, MDN, caniuse.com) to guide the agent towards trusted documentation sites.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation from external web sources to ensure implementation correctness.\n
  • Evidence: Mentions fetching from established documentation services such as react.dev, docs.djangoproject.com, symfony.com, nextjs.org, caniuse.com, and node.green (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — source-driven-development