cross-layer-drift-sweep

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and process untrusted external data, which creates a surface for indirect prompt injection attacks.
  • Ingestion points: The SKILL.md file directs the agent to search through "source, comments, tests, fixtures, snapshots and relevant documentation".
  • Boundary markers: The instructions lack explicit delimiters or warnings to the agent to disregard potential instructions embedded within the files being searched.
  • Capability inventory: The agent is authorized to perform file writes ("Fix mismatches") and execute downstream workflows via the testing-workflow and verify-all-runtime-sinks skills.
  • Sanitization: There is no evidence of content sanitization or validation before the agent acts upon the gathered information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 10:32 PM
Security Audit — agent-trust-hub — cross-layer-drift-sweep