learn-codebase
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to read "EVERY SOURCE FILE IN FULL" without any exclusion criteria. This poses a significant risk of data exposure if the codebase contains sensitive files such as
.envfiles, configuration files with hardcoded secrets, or private keys, as these would be loaded directly into the AI's active context. - [PROMPT_INJECTION]: The instructions use imperative and overriding language ("This is critical and non negotiable") intended to force the agent to ignore any internal logic or safety filters that might otherwise suggest skipping large or sensitive files.
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality creates a large attack surface for indirect prompt injection by ingesting untrusted source code into the agent's context.
- Ingestion points: The local filesystem via the
Readtool (SKILL.md). - Boundary markers: Absent; there are no instructions to use delimiters or to treat the file content as untrusted data.
- Capability inventory: The skill utilizes the
Readtool to systematically ingest file content. - Sanitization: Absent; the content is read "in full" without any filtering or sanitization of embedded instructions.
Audit Metadata