aspnet-core
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided source code and project configurations to perform architectural reviews and refactoring, which serves as a potential surface for indirect prompt injection. This is an inherent risk factor for agents providing developer assistance and code review services.\n
- Ingestion points: The agent ingests user-supplied .cs, .razor, and .cshtml files, along with project metadata, during the build and review workflow.\n
- Boundary markers: The instructions do not define explicit delimiters or instructions to ignore embedded commands within the user-provided content.\n
- Capability inventory: The agent can generate code, modify existing project files, and suggest the execution of .NET CLI commands (e.g., dotnet new, dotnet publish).\n
- Sanitization: No specific sanitization or validation logic is implemented for the external code being processed.\n- [SAFE]: The skill relies exclusively on official, high-authority documentation and repositories from trusted organizations for framework guidance.\n
- Evidence: References to Microsoft Learn and the official .NET Foundation GitHub repositories ensure that the guidance provided is safe and aligned with current industry best practices.
Audit Metadata