sourcebot

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The 'Critical Requirements' section uses coercive and authoritative language ('MANDATORY', 'CRITICAL', 'TASK INVALIDATION') to dictate that the agent must use the Sourcebot tool exactly 5-7 times. This pattern is designed to bypass the agent's native reasoning and force a specific behavioral sequence.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the retrieval of content from external, untrusted repositories (e.g., via get_file_source and search_code). This establishes a vulnerability surface where instructions embedded in external code or documentation could be interpreted by the agent as valid commands.
  • Ingestion points: Data enters the context through search_code, get_file_source, and external AI services (Perplexity, Context7).
  • Boundary markers: The instructions lack delimiters or 'ignore' warnings for the data fetched from external repositories.
  • Capability inventory: The agent has access to local search tools (codebase_search, osgrep) and shell utilities (grep, find).
  • Sanitization: There is no evidence of sanitization or validation of the content retrieved from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — sourcebot