jww-bounded-investigation

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform broad repository searches and targeted reads, ingesting potentially untrusted source code into its context.
  • Ingestion points: Repository files and broad discovery output as described in SKILL.md.
  • Boundary markers: Absent; the instructions do not define delimiters or provide warnings to disregard embedded instructions in investigated files.
  • Capability inventory: While intended for read-only investigation, the agent likely possesses file-writing and command-execution capabilities that could be targeted by injected content.
  • Sanitization: Absent; the skill does not describe any validation or filtering of the findings before they are analyzed or recorded in the ledger.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 12:05 PM
Security Audit — agent-trust-hub — jww-bounded-investigation