workspace-validator
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses potentially untrusted data from validation hook outputs to drive code changes, creating a surface for indirect prompt injection.
- Ingestion points: Error messages and hook outputs are ingested from the
rm_projectstool'sfailed_detailsoutput field. - Boundary markers: No specific delimiters or safety instructions are defined to separate the tool output from the agent's core instructions during the remediation loop.
- Capability inventory: The agent possesses high-impact capabilities including file system modifications, staging, committing, and pushing code to remote repositories.
- Sanitization: There are no requirements for the agent to validate or sanitize hook output before generating code fixes based on that content.
Audit Metadata