sgc-install-ai

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze an application's stack and runtime surfaces to generate integration code and UI. This creates a surface where malicious instructions embedded in the target application's source code or documentation could potentially influence the agent's behavior during the integration process.
  • Ingestion points: The workflow in SKILL.md (Step 0 and Step 1) involves inspecting the target application's source code, backend boundaries, and existing project context.
  • Boundary markers: The skill uses specific reference files (references/user-config.md, references/runtime-routing.md) to guide the agent, and explicitly instructs it to ignore implementation details like provider names or internal notes in the final user-facing UI.
  • Capability inventory: The agent is expected to create feature contracts, adapter code, and UI components in the target project's filesystem.
  • Sanitization: The skill includes a mandatory validation step (Step 4) to verify that no credentials, internal routes, or private prompts appear in source code or network payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:07 PM
Security Audit — agent-trust-hub — sgc-install-ai