itsol-current-tech-context

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to read and process data from local repository manifests (e.g., package.json, Cargo.toml, Directory.Build.props, OpenAPI specs) and external sources such as package registries (npm, crates.io, NuGet) and documentation. This ingestion of untrusted external content creates a vulnerability to indirect prompt injection, where malicious instructions hidden in metadata or documentation could attempt to steer the agent's behavior during planning and review.\n
  • Ingestion points: Local configuration files (manifests, lockfiles, toolchain files) and external documentation/registries (npm, crates.io, NuGet, GitHub releases).\n
  • Boundary markers: The instructions lack explicit requirements for the agent to use delimiters or safety prompts to ignore instructions embedded within the ingested technical data.\n
  • Capability inventory: The skill is used to generate planning and review output; it does not define executable scripts or direct system modification capabilities.\n
  • Sanitization: There are no instructions for sanitizing or validating the content retrieved from external sources before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — itsol-current-tech-context