technical-audit

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process untrusted content from external URLs and local project files without explicit boundary markers or instructions to isolate or ignore instructions embedded in that content. This creates a surface for indirect prompt injection.\n
  • Ingestion points: Analysis of website content and local source code.\n
  • Boundary markers: Not used in the instructions to separate data from agent control.\n
  • Capability inventory: Ability to execute shell commands via Node.js and npm.\n
  • Sanitization: No specified sanitization for data retrieved during audits.\n- [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands like node technical-audit/checks.js and npm run tasks. Although these are functional requirements, they represent a capability level that handles user-provided inputs like URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 01:16 PM
Security Audit — agent-trust-hub — technical-audit