drupal-new-module
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-supplied descriptions to generate Drupal module code, creating an ingestion point for untrusted data.
- Ingestion points: The module creation workflow in
SKILL.mdtakes a description and requirements from the user. - Boundary markers: The skill relies on robust reference files to constrain the agent's output but does not implement explicit boundary delimiters in the prompt interpolation.
- Capability inventory: The agent uses
WriteandBashtools to create and interact with the filesystem. - Sanitization: The risk is mitigated by the inclusion of comprehensive security guidelines in
references/10-security.mdwhich enforce safe coding patterns like parameterization and CSRF protection. - [EXTERNAL_DOWNLOADS]: The skill documentation references external asset libraries for frontend development.
- Evidence:
references/11-theming.mdspecifies the use of the Swiper library via the well-knownunpkg.comCDN for theme definitions.
Audit Metadata