sgc-install-ai
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze an application's stack and runtime surfaces to generate integration code and UI. This creates a surface where malicious instructions embedded in the target application's source code or documentation could potentially influence the agent's behavior during the integration process.
- Ingestion points: The workflow in
SKILL.md(Step 0 and Step 1) involves inspecting the target application's source code, backend boundaries, and existing project context. - Boundary markers: The skill uses specific reference files (
references/user-config.md,references/runtime-routing.md) to guide the agent, and explicitly instructs it to ignore implementation details like provider names or internal notes in the final user-facing UI. - Capability inventory: The agent is expected to create feature contracts, adapter code, and UI components in the target project's filesystem.
- Sanitization: The skill includes a mandatory validation step (Step 4) to verify that no credentials, internal routes, or private prompts appear in source code or network payloads.
Audit Metadata