dotnet-core-expert
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
dotnetCLI for compilation (dotnet build) and verification (dotnet test). It also utilizescurlfor functional testing of API endpoints as part of the core development workflow. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its operational model:
- Ingestion points: The agent processes user-provided C# source files, project configurations (.csproj), and appsettings.json files (e.g., in
SKILL.mdandreferences/cloud-native.md). - Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the code it processes.
- Capability inventory: The agent has the capability to execute the code it processes or generates via the
dotnet testcommand. - Sanitization: No sanitization or validation of the contents of the ingested project files is specified before the agent performs implementation or testing tasks.
Audit Metadata