spring-boot-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a potential attack surface for indirect prompt injection by processing external user requirements to generate executable code.\n
- Ingestion points: Steps 1 and 2 of the core workflow in
SKILL.mdinvolve analyzing user-provided requirements and designs.\n - Boundary markers: There are no specified delimiters or instructions to prevent the agent from obeying instructions embedded in the requirements.\n
- Capability inventory: The skill uses shell commands (
./mvnw test,./gradlew test) and network access (/actuator/health) to validate the generated code.\n - Sanitization: No sanitization or validation of requirements is mentioned before they influence code generation.\n- [PROMPT_INJECTION]: Metadata authorship discrepancy: The
authorfield inSKILL.md(Jeffallan) differs from the identified vendor (Krypton-Kr36). This discrepancy in authorship metadata can be misleading regarding the skill's origin.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell-based build tools (mvnw,gradlew) and perform health checks on service endpoints. These capabilities are intended for development but increase the potential impact of the identified injection surface.
Audit Metadata