ship-safe
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (source code and configuration files), which is a standard surface for indirect prompt injection.
- Ingestion points: The skill instructs the agent to scan all source code files and check all configuration files.
- Boundary markers: There are no explicit instructions for the agent to use delimiters or warnings to ignore instructions found within the scanned files.
- Capability inventory: The skill has access to powerful tools including
Bash,Read,Grep, andGlobacross all files. - Sanitization: No specific sanitization or validation logic is defined for the content extracted from the files before it is processed by the agent.
Audit Metadata