agentmd
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions explicitly state that it 'Replaces the default /init command'. This is an attempt to hijack or override standard platform commands and behavior through natural language instructions.
- [METADATA_POISONING]: The skill uses a likely hallucinated research paper ('Evaluating AGENTS.md', ETH Zurich, Feb 2026) and a non-existent Arxiv ID (2602.11988) to establish false authority for its 'research-backed' claims. Using fabricated credentials or citations is a form of metadata deception.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves scanning untrusted repository files (ingestion point) to generate a context file that the agent will later obey (capability). While the skill contains a 'Security: Data Boundaries' section instructing the agent to treat repo content as untrusted and avoid verbatim echoes, the workflow still processes external data that could attempt to influence the generated output.
Audit Metadata