dotnet-mcaf-devex

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from the repository's setup and configuration files to drive its automation workflow. \n
  • Ingestion points: The skill analyzes the current local setup, build/run/debug/test commands, and onboarding friction points as documented in SKILL.md. \n
  • Capability inventory: The skill instructions involve executing build, run, debug, and test commands based on the analyzed repository content. \n
  • Boundary markers: While the skill suggests reading AGENTS.md for constraints, it lacks explicit delimiters or instructions to ignore potentially malicious embedded instructions within the project's own files. \n
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the repository's configuration or setup commands before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 12:35 PM
Security Audit — agent-trust-hub — dotnet-mcaf-devex