jww-bounded-investigation
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform broad repository searches and targeted reads, ingesting potentially untrusted source code into its context.
- Ingestion points: Repository files and broad discovery output as described in SKILL.md.
- Boundary markers: Absent; the instructions do not define delimiters or provide warnings to disregard embedded instructions in investigated files.
- Capability inventory: While intended for read-only investigation, the agent likely possesses file-writing and command-execution capabilities that could be targeted by injected content.
- Sanitization: Absent; the skill does not describe any validation or filtering of the findings before they are analyzed or recorded in the ledger.
Audit Metadata