klaviyo-reference-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a feature to review existing projects by reading and grepping through code files, which creates a vulnerability surface for instructions embedded in those files. 1. Ingestion points: Source code read from the local file system during review tasks. 2. Boundary markers: None specified in the instructions to differentiate agent instructions from analyzed content. 3. Capability inventory: Access to Read, Write, Edit, and Grep tools which are used to process the ingested content. 4. Sanitization: No sanitization or validation of the analyzed source code is performed before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:43 AM
Security Audit — agent-trust-hub — klaviyo-reference-architecture