spring-boot-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a potential attack surface for indirect prompt injection by processing external user requirements to generate executable code.\n
  • Ingestion points: Steps 1 and 2 of the core workflow in SKILL.md involve analyzing user-provided requirements and designs.\n
  • Boundary markers: There are no specified delimiters or instructions to prevent the agent from obeying instructions embedded in the requirements.\n
  • Capability inventory: The skill uses shell commands (./mvnw test, ./gradlew test) and network access (/actuator/health) to validate the generated code.\n
  • Sanitization: No sanitization or validation of requirements is mentioned before they influence code generation.\n- [PROMPT_INJECTION]: Metadata authorship discrepancy: The author field in SKILL.md (Jeffallan) differs from the identified vendor (Krypton-Kr36). This discrepancy in authorship metadata can be misleading regarding the skill's origin.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell-based build tools (mvnw, gradlew) and perform health checks on service endpoints. These capabilities are intended for development but increase the potential impact of the identified injection surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:52 PM
Security Audit — agent-trust-hub — spring-boot-engineer