files
Pass
Audited by Gen Agent Trust Hub on Mar 20, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill defines a functionality to list user-uploaded files, which presents a surface for indirect prompt injection where the agent might interpret instructions embedded in file names or metadata.
- Ingestion points: File names and metadata from Lab Nocturne entering the agent's context.
- Boundary markers: No delimiters or 'ignore instructions' warnings are defined in this file.
- Capability inventory: No active capabilities (e.g., shell execution, network calls) are defined in this alias file.
- Sanitization: No sanitization or validation of external metadata is specified.
- [NO_CODE]: No executable code, shell commands, or software package dependencies are present in this configuration file.
Audit Metadata