minimal
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing external inputs such as user requests, existing repository code, and data from untrusted boundaries (e.g., URLs, network responses, and files).
- Ingestion points: The agent is instructed to ingest data from user requests, repository code, and external interfaces defined in
references/decision-rules.md. - Boundary markers: The instructions include a 'Simplicity gate' and a 'Task contract' to limit the scope of actions and explicitly call for validation at system boundaries.
- Capability inventory: The skill allows the agent to modify code, create files, and review existing logic based on the processed inputs.
- Sanitization: The skill explicitly mandates validation at boundaries (input, storage, network) to establish trusted internal contracts, which serves as a security best practice to mitigate injection risks.
Audit Metadata