workspace-validator

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses potentially untrusted data from validation hook outputs to drive code changes, creating a surface for indirect prompt injection.
  • Ingestion points: Error messages and hook outputs are ingested from the rm_projects tool's failed_details output field.
  • Boundary markers: No specific delimiters or safety instructions are defined to separate the tool output from the agent's core instructions during the remediation loop.
  • Capability inventory: The agent possesses high-impact capabilities including file system modifications, staging, committing, and pushing code to remote repositories.
  • Sanitization: There are no requirements for the agent to validate or sanitize hook output before generating code fixes based on that content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 02:02 AM
Security Audit — agent-trust-hub — workspace-validator