distill
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The distillation process described in the skill involves ingesting and analyzing untrusted source code from existing codebases. This activity presents a surface for indirect prompt injection, where malicious instructions hidden within the analyzed code (such as in comments or strings) could influence the agent's behavior. The orchestration model, which suggests fanning out to subagents for different parts of the codebase, further distributes this attack surface.
- Ingestion points: The process involves reading codebase entry points, domain models, and business logic as defined in the mapping and extraction steps (SKILL.md).
- Boundary markers: No instructions are provided for using delimiters or boundary markers to isolate untrusted code content from the agent's core instructions.
- Capability inventory: The skill assumes capabilities to read file contents, navigate directories, and generate new specification files.
- Sanitization: There are no instructions for sanitizing or escaping the content read from the source files before it is processed by the model.
Audit Metadata