check-reasonix-update

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it fetches and summarizes external data from a public repository without adequate safeguards.\n
  • Ingestion points: Step 2 and Step 4 of the workflow use web_fetch to retrieve content from https://github.com/esengine/DeepSeek-Reasonix/releases.\n
  • Boundary markers: The instructions lack explicit delimiters or specific commands to the agent to disregard instructions that might be embedded within the fetched release notes.\n
  • Capability inventory: The skill is granted file system capabilities to list, read, and write files within the ./ReasonixUpdateLog/ directory, which could be misused if the agent is manipulated by malicious input in the release notes.\n
  • Sanitization: There is no evidence of content sanitization or validation performed on the remote data before it is incorporated into the generated reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 02:02 AM
Security Audit — agent-trust-hub — check-reasonix-update