learn-codebase

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to read "EVERY SOURCE FILE IN FULL" without any exclusion criteria. This poses a significant risk of data exposure if the codebase contains sensitive files such as .env files, configuration files with hardcoded secrets, or private keys, as these would be loaded directly into the AI's active context.
  • [PROMPT_INJECTION]: The instructions use imperative and overriding language ("This is critical and non negotiable") intended to force the agent to ignore any internal logic or safety filters that might otherwise suggest skipping large or sensitive files.
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality creates a large attack surface for indirect prompt injection by ingesting untrusted source code into the agent's context.
  • Ingestion points: The local filesystem via the Read tool (SKILL.md).
  • Boundary markers: Absent; there are no instructions to use delimiters or to treat the file content as untrusted data.
  • Capability inventory: The skill utilizes the Read tool to systematically ingest file content.
  • Sanitization: Absent; the content is read "in full" without any filtering or sanitization of embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — learn-codebase