sourcebot
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The 'Critical Requirements' section uses coercive and authoritative language ('MANDATORY', 'CRITICAL', 'TASK INVALIDATION') to dictate that the agent must use the Sourcebot tool exactly 5-7 times. This pattern is designed to bypass the agent's native reasoning and force a specific behavioral sequence.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the retrieval of content from external, untrusted repositories (e.g., via
get_file_sourceandsearch_code). This establishes a vulnerability surface where instructions embedded in external code or documentation could be interpreted by the agent as valid commands. - Ingestion points: Data enters the context through
search_code,get_file_source, and external AI services (Perplexity, Context7). - Boundary markers: The instructions lack delimiters or 'ignore' warnings for the data fetched from external repositories.
- Capability inventory: The agent has access to local search tools (
codebase_search,osgrep) and shell utilities (grep,find). - Sanitization: There is no evidence of sanitization or validation of the content retrieved from external sources.
Audit Metadata