secure-ai-agent-coding
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest and analyze external, untrusted codebases through
scripts/scan_patterns.py. - Ingestion points:
scripts/scan_patterns.pyreads the content of arbitrary text files within a target directory provided as a command-line argument. - Boundary markers: While the skill documentation in
references/implementation-patterns.mdstrongly advocates for the use of boundary markers (e.g.,<untrusted_user_data>tags), the heuristic scanner script itself reads raw file content directly into regex engines. - Capability inventory: The skill has the capability to read local files, write JSON results to stdout, and execute internal scripts via
subprocess.runin the test suite. - Sanitization: The scanner does not sanitize the input files; it performs heuristic regex matching to identify potential vulnerabilities for human review.
- [COMMAND_EXECUTION]: The testing script
scripts/test_skill.pyutilizes thesubprocess.runmodule to execute other scripts within the skill's package. - Evidence:
scripts/test_skill.pyexecutesscripts/validate.pyandscripts/scan_patterns.pyusingsys.executable. - Context: These executions are used for validating the skill's integrity and functionality. The commands are constructed using fixed paths relative to the skill root, minimizing injection risks.
Audit Metadata