lucidchart-upgrade-migration

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow that ingests untrusted or external data, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: External documentation fetched via WebFetch from official Lucid developer domains and local project files accessed using Read, Glob, and Grep.\n
  • Boundary markers: The skill body lacks explicit instructions or delimiters to isolate the agent from potentially malicious instructions embedded in the ingested content.\n
  • Capability inventory: The skill is authorized to use Write and Edit tools, which enable the modification of project source code, dependencies, and configuration files across the file system.\n
  • Sanitization: There are no documented mechanisms for sanitizing or validating the content retrieved from external sources or local project files before it influences the agent's suggested modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:11 AM
Security Audit — agent-trust-hub — lucidchart-upgrade-migration