ghostbill-fullstack-v2
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The file
references/source-prompt.mduses authoritative override language, stating it is "self-contained and authoritative" and "supersedes the specialized backend and frontend prompts where they conflict." This is a common technique to ensure strict adherence to a provided specification by overriding the model's default behaviors or conflicting context. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to build an application that processes untrusted external input (bank transaction files in CSV, XLSX, JSON, and PDF formats). While the skill itself does not process this data, it instructs the agent to create logic that ingests these sources, creating a potential attack surface for indirect prompt injection if malicious instructions were embedded in transaction data during the implementation or testing phases.
- Ingestion points:
references/source-prompt.mddefines parsers for multiple external file formats (CSV, XLSX, JSON, PDF). - Boundary markers: There are no specific instructions for the agent to use delimiters or sanitization logic to separate transaction data from its own execution context during testing.
- Capability inventory: The agent is given capabilities to scaffold projects, write source code, install packages, and execute builds/tests.
- Sanitization: The instructions focus on regex for data extraction but do not explicitly address sanitization against prompt injection or command injection in the built application.
Audit Metadata