setup

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided model names and access descriptions and writes them into system-level instruction files used by other agents, creating a potential vector for indirect prompt injection. \n
  • Ingestion points: User responses to questions about image/video model names, access methods, and folder paths (interview section in SKILL.md). \n
  • Boundary markers: Absent; user input is interpolated directly into a Markdown list format within CLAUDE.md and AGENTS.md without delimiters like XML tags or explicit 'ignore embedded instructions' warnings. \n
  • Capability inventory: The skill possesses file-write capabilities across the project directory, specifically targeting CLAUDE.md and AGENTS.md. \n
  • Sanitization: The skill explicitly instructs the agent to avoid recording secret values (API keys), but provides no instructions for sanitizing or escaping general text input that could contain malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 02:31 PM
Security Audit — agent-trust-hub — setup