recommend-prune

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes output from 'audit-drift' and section maps to generate cleanup proposals. Malicious instructions embedded in these data sources could theoretically influence the agent's reasoning during proposal generation.
  • Ingestion points: Processes external data from 'audit-drift' reports and project section maps (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands when interpolating data into the prompt.
  • Capability inventory: The skill's capabilities are limited to generating text proposals; it explicitly states it 'does not execute' actions.
  • Sanitization: There is no evidence of validation or sanitization of the input data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:36 PM
Security Audit — agent-trust-hub — recommend-prune