research
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest data from untrusted external primary sources, creating a potential surface for indirect prompt injection.
- Ingestion points: Processes content from external documentation, source code, and APIs (SKILL.md).
- Boundary markers: Absent; there are no instructions to delimit or ignore instructions within the ingested data.
- Capability inventory: Includes the ability to write files to the repository (SKILL.md).
- Sanitization: Absent; no sanitization or validation of external content is specified.
Audit Metadata