project-discovery
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface detected where the skill ingests untrusted data from the local repository.\n * Ingestion points: The
scripts/discover.shscript and manual workflows inREFERENCE.mdread content fromREADME.md,package.json, and git commit logs (e.g.,git log --oneline).\n * Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potential instructions embedded within these files.\n * Capability inventory: The skill is grantedBash,Read,Grep,Glob, andTodoWritetools inSKILL.md, allowing for file system interaction and shell execution.\n * Sanitization: The skill does not sanitize or escape the content read from the repository before presenting it to the agent context.
Audit Metadata