app-user-story-qa

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it relies on reading and interpreting untrusted data from the repository's source code and documentation to drive its testing and inventory logic.
  • Ingestion points: The agent ingests untrusted data from local source code, documentation (README, AGENTS.md), architecture diagrams, API definitions, and CLI flag specifications as described in SKILL.md.
  • Boundary markers: The skill lacks instructions for the agent to use delimiters or explicit 'ignore embedded instructions' markers when processing content from the audited files.
  • Capability inventory: The agent is authorized to execute shell commands to perform repository snapshots and run local tests, and it has file-writing capabilities to maintain a canonical CSV tracker and apply code fixes in authorized modes.
  • Sanitization: There are no procedures defined for validating, escaping, or filtering instructions that might be embedded within the audited code or documentation before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 12:35 AM
Security Audit — agent-trust-hub — app-user-story-qa