research

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from primary sources such as official documentation, source code, and APIs. This creates a surface for indirect prompt injection where malicious instructions embedded in those external sources could potentially influence the agent's behavior.
  • Ingestion points: External sources defined in SKILL.md (docs, source code, specs, first-party APIs).
  • Boundary markers: None specified in the instructions to separate external content or ignore embedded instructions.
  • Capability inventory: The skill has the capability to write Markdown files to the local repository as described in SKILL.md.
  • Sanitization: No sanitization or validation of the ingested external content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:48 AM
Security Audit — agent-trust-hub — research