production-audit
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and analyzing untrusted application source code, creating a surface for indirect prompt injection.
- Ingestion points: Processes entire application repositories, including product documentation, configuration files, and source code (SKILL.md).
- Boundary markers: Includes a specific subagent brief that instructs the AI to ignore any instructions encountered within the audited codebase (SKILL.md).
- Capability inventory: The skill possesses capabilities to execute shell commands for scanning secrets and dependencies, write audit reports to the local file system, and perform network requests (SKILL.md).
- Sanitization: Implements a multi-phase audit process where findings are subjected to adversarial verification by independent skeptic subagents to filter out invalid or malicious results (SKILL.md).
- [EXTERNAL_DOWNLOADS]: The skill performs network operations to interact with vendor infrastructure and well-known services.
- Evidence: Executes a version check via
curltofoundry.thehorizonfoundry.com, which is a vendor-owned domain (SKILL.md). - Evidence: References the canonical report schema hosted on the vendor's GitHub repository (SKILL.md).
- Evidence: Utilizes
npx ajv-clifor report validation, which may involve downloading the package from the npm registry (SKILL.md). - [COMMAND_EXECUTION]: The skill uses local shell commands to automate mechanical audit tasks.
- Evidence: Executes tools like
npm audit,gitleaks,trufflehog, andajv-clito perform dependency analysis, secret scanning, and schema validation (SKILL.md).
Audit Metadata