files

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a functionality to list user-uploaded files, which presents a surface for indirect prompt injection where the agent might interpret instructions embedded in file names or metadata.
  • Ingestion points: File names and metadata from Lab Nocturne entering the agent's context.
  • Boundary markers: No delimiters or 'ignore instructions' warnings are defined in this file.
  • Capability inventory: No active capabilities (e.g., shell execution, network calls) are defined in this alias file.
  • Sanitization: No sanitization or validation of external metadata is specified.
  • [NO_CODE]: No executable code, shell commands, or software package dependencies are present in this configuration file.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 12:30 AM
Security Audit — agent-trust-hub — files