secure-auth

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an adaptive research workflow that requires the agent to gather real-time data from external sources, which creates a potential exposure to indirect prompt injection if those sources are compromised.
  • Ingestion points: In SKILL.md under 'Step 0: Research the current security landscape', the agent is explicitly instructed to search and ingest data from package registries (such as registry.npmjs.org, pypi.org), the CISA KEV catalog, and public practitioner discourse (including various external security vendor blogs and conference write-ups).
  • Boundary markers: Absent. There are no clear prompt boundaries, XML tags, or strict instructions specified to encapsulate the external search results or to alert the agent to disregard formatting or commands embedded within the retrieved third-party text.
  • Capability inventory: The skill does not include automated execution scripts, but it directs the agent to execute shell commands (npm install, npx esbuild) and contains production-like application code blocks for authentication routing, password reset, and database persistence.
  • Sanitization: Absent. There is no filter or verification mechanism applied to the data retrieved from external blogs or package registries. The skill explicitly directs the agent to let the external synthesis override internal templates ('The synthesis wins. The skill body is scaffolding, not scripture'), creating a path for poisoned inputs to alter agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:01 AM
Security Audit — agent-trust-hub — secure-auth