agent-definition-fix

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file instructs users to execute a local Python script fix_agent_definitions.py to perform repairs. \n- [DATA_EXPOSURE]: The script fix_agent_definitions.py reads and modifies files in the ~/.gemini/agents/ directory. While this directory contains agent instructions and configurations, no credentials or private keys are targeted. \n- [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to programmatically modify files that contain agent instructions, which represents an attack surface for indirect prompt injection. \n
  • Ingestion points: The script reads all .md files in the ~/.gemini/agents/ directory. \n
  • Boundary markers: No boundary markers or specific ignore instructions are used when processing the files. \n
  • Capability inventory: The script has file-write capabilities (open(filepath, 'w')) used to update agent definition content. \n
  • Sanitization: Content is modified using specific regular expressions for 'color' and 'tools' keys, but the rest of the file content is not validated or sanitized.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:08 PM
Security Audit — agent-trust-hub — agent-definition-fix