lucidchart-ci-integration

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository files and external documentation, which could contain malicious instructions designed to influence the agent.
  • Ingestion points: The agent utilizes Read, Glob, and Grep tools to inspect manifests, code, and test fixtures within the target repository. It also uses WebFetch to retrieve content from external documentation sites (specifically developer.lucid.co).
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when processing content from the repository or fetched documentation.
  • Capability inventory: The skill includes the ability to modify files via Write and Edit and perform network requests via WebFetch.
  • Sanitization: The skill mandates the use of sanitized fixtures and the creation of redacted receipts, which helps prevent accidental data exposure but does not fully mitigate the risk of the agent following malicious instructions embedded in the analyzed code or documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:11 AM
Security Audit — agent-trust-hub — lucidchart-ci-integration