frappe-syntax-hooks-events
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructional content and code examples for the Frappe framework. The content is educational in nature and aligns with established development practices for that platform.\n- [PROMPT_INJECTION]: The skill describes mechanisms for an agent to process document data via event hooks, which represents an indirect prompt injection surface.\n
- Ingestion points: Document object fields processed in event handlers like validate or on_submit (SKILL.md, references/examples.md).\n
- Boundary markers: None present in the provided code snippets.\n
- Capability inventory: Database operations (doc.db_set, doc.insert), background task processing (frappe.enqueue), and automated email dispatch (frappe.sendmail) (references/examples.md).\n
- Sanitization: Not explicitly mentioned in the instructional snippets, which focus on framework logic.\n- [SAFE]: A metadata discrepancy was noted where the author in the frontmatter ('OpenAEC-Foundation') does not match the system-identified author ('Impertio-Studio'). This appears to be a documentation oversight rather than a malicious attempt at deception.
Audit Metadata