github-readme
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection because it processes untrusted data from external repositories and URLs to inform its output.\n
- Ingestion points: Workflow Step 2 in SKILL.md directs the agent to extract information from the repository file tree, local files, existing READMEs, and provided GitHub URLs.\n
- Boundary markers: The instructions do not specify the use of delimiters or "ignore embedded instructions" markers when reading external file content.\n
- Capability inventory: The agent performs file system reads and URL fetches (via available tools) to verify technical specifications like script names, directory structures, and environment variable keys.\n
- Sanitization: There is no requirement for the agent to sanitize or validate the content retrieved from external sources before processing it.
Audit Metadata