csharp
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted code and project files, creating an attack surface for indirect prompt injection.
- Ingestion points: The skill is triggered by and reads content from
.cs,.csproj,.sln, and.razorfiles. - Boundary markers: The instructions do not define explicit delimiters or instructions to ignore embedded commands within the code files it processes.
- Capability inventory: The 'Verification Checklist' instructs the agent to execute shell-based tools including
dotnet buildanddotnet test, which involve subprocess execution. - Sanitization: There is no mention of sanitizing or escaping content read from files before it is processed by the agent or included in shell commands.
Audit Metadata