skills/moontory/skills/explore/Gen Agent Trust Hub

explore

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill performs deep code investigations by reading implementations, entry points, and configurations within a repository. This creates an attack surface where malicious instructions hidden in source code (e.g., inside comments, string literals, or documentation) could attempt to influence the agent's reasoning or behavior during the exploration process.
  • Ingestion points: Source code implementations, configuration files, and tests identified during investigation (SKILL.md).
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' prefixes when reading and processing code content.
  • Capability inventory: The skill is limited to read-only file access and reporting findings. It explicitly prohibits file modifications, agent spawning, or delegation (SKILL.md).
  • Sanitization: Absent. There is no mention of filtering or sanitizing content retrieved from the repository files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:18 AM
Security Audit — agent-trust-hub — explore