improve-getting-started

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes documentation files from the repository which could contain adversarial instructions that the agent might inadvertently follow during the audit.
  • Ingestion points: The skill reads content from README.md, CONTRIBUTING.md, docs/, package.json, and .env.example using the cat command.
  • Boundary markers: The instructions lack specific delimiters or guardrails to differentiate between the skill's instructions and the content being audited, increasing the risk that the agent obeys commands found within the project files.
  • Capability inventory: The skill is authorized to perform file system operations (ls, cat), git operations (git log), and is directed to verify or execute setup commands found in the documentation (e.g., npm install, docker compose, npm test).
  • Sanitization: There is no evidence of content sanitization or filtering applied to the data read from the repository files before it enters the agent's context.
  • [COMMAND_EXECUTION]: The skill uses local shell commands to inspect the project environment and state.
  • Evidence: Uses ls, cat, node --version, and git log to discover configuration files, read dependency manifests, and verify installed tool versions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — improve-getting-started