drupal-new-module

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user-supplied descriptions to generate Drupal module code, creating an ingestion point for untrusted data.
  • Ingestion points: The module creation workflow in SKILL.md takes a description and requirements from the user.
  • Boundary markers: The skill relies on robust reference files to constrain the agent's output but does not implement explicit boundary delimiters in the prompt interpolation.
  • Capability inventory: The agent uses Write and Bash tools to create and interact with the filesystem.
  • Sanitization: The risk is mitigated by the inclusion of comprehensive security guidelines in references/10-security.md which enforce safe coding patterns like parameterization and CSRF protection.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references external asset libraries for frontend development.
  • Evidence: references/11-theming.md specifies the use of the Swiper library via the well-known unpkg.com CDN for theme definitions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 07:10 PM
Security Audit — agent-trust-hub — drupal-new-module