cross-layer-drift-sweep
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and process untrusted external data, which creates a surface for indirect prompt injection attacks.
- Ingestion points: The
SKILL.mdfile directs the agent to search through "source, comments, tests, fixtures, snapshots and relevant documentation". - Boundary markers: The instructions lack explicit delimiters or warnings to the agent to disregard potential instructions embedded within the files being searched.
- Capability inventory: The agent is authorized to perform file writes ("Fix mismatches") and execute downstream workflows via the
testing-workflowandverify-all-runtime-sinksskills. - Sanitization: There is no evidence of content sanitization or validation before the agent acts upon the gathered information.
Audit Metadata