aiwg-regenerate-cursorrules

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by reading content from project files (README.md, package.json) and interpolating it into the generated configuration. This is the primary intended function of the skill.\n
  • Ingestion points: README.md, package.json, and preserved sections of .cursorrules (SKILL.md).\n
  • Boundary markers: Employs and markers to distinguish user content.\n
  • Capability inventory: Modifies .cursorrules, which defines the AI agent's operational context in the Cursor IDE.\n
  • Sanitization: No explicit sanitization is performed on the content extracted from project files.\n- [COMMAND_EXECUTION]: The skill identifies and documents project development commands (e.g., npm install) within the generated rules file for user reference, but does not invoke these commands itself.\n- [SAFE]: The skill performs routine file management by reading project metadata and writing configuration files. No malicious patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 06:27 PM
Security Audit — agent-trust-hub — aiwg-regenerate-cursorrules