windsurf-cascade-context
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests arbitrary project data to map codebase structure and maintain documentation. 1. Ingestion points: Instructions in
references/implementation.mddescribe reading and documenting project files likeapi-surface.mdandproject-overview.md. 2. Boundary markers: No delimiters or protective instructions are specified to prevent the agent from obeying commands embedded in project documentation. 3. Capability inventory: The skill is configured to useRead,Write,Edit,Grep, andGlobtools for file management. 4. Sanitization: The skill does not implement validation or sanitization for the project content it processes. - [NO_CODE]: The skill consists exclusively of Markdown documentation files providing workflow guidance and does not include any Python, JavaScript, shell scripts, or other executable code.
Audit Metadata