ai-steering-files

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified in the skill instructions.
  • [NO_CODE]: This skill consists of markdown guidelines and does not contain scripts or executable commands.
  • [PROMPT_INJECTION]: The skill instructions create an indirect prompt injection surface by directing the agent to read and audit various repository files that can contain instructions.
  • Ingestion points: Reads files like AGENTS.md, CLAUDE.md, and .cursor/rules/*.mdc (File: SKILL.md).
  • Boundary markers: No instructions are provided to the agent to treat file content as untrusted or to use delimiters.
  • Capability inventory: The agent typically holds file read/write permissions while executing these tasks.
  • Sanitization: There is no requirement or guidance for the agent to sanitize the content of the steering files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 01:02 AM
Security Audit — agent-trust-hub — ai-steering-files