java-spring

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with user-controlled files, providing a vector for indirect prompt injection.
  • Ingestion points: The skill reads project files including pom.xml, build.gradle.kts, and Java source code as part of its core functionality.
  • Boundary markers: The skill does not employ delimiters to isolate user code from instructions.
  • Capability inventory: The skill facilitates shell command execution via Maven and Gradle wrappers for building and running applications.
  • Sanitization: The skill lacks explicit sanitization routines for the data it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 03:14 PM
Security Audit — agent-trust-hub — java-spring