eli12
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and explain external codebase files, creating a surface for indirect prompt injection if those files contain malicious instructions.
- Ingestion points: The agent is instructed to read real code paths, functions, and models to build mental models (
references/explorer-prompt.md). - Boundary markers: The instructions do not include specific delimiters or 'ignore' commands to protect the agent from acting on instructions found within the code comments or documentation it analyzes.
- Capability inventory: The skill uses tools for searching symbols, reading files, and tracing paths, but it does not have write access or network capabilities according to its routing logic (
SKILL.md). - Sanitization: There is no mention of filtering or sanitizing the content of the files before the agent processes them.
Audit Metadata