ns-harness-bootstrap-brownfield

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted metadata from external codebases (such as module names, configuration keys, and file structures) to generate reports used by other agents, creating a surface for indirect prompt injection.
  • Ingestion points: Reads project configuration files including package.json, composer.json, docker-compose.yml, and directory structures to map modules (SKILL.md, Workflow Steps 1 & 2).
  • Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore' instructions when interpolating discovered code data into the brownfield-map.md report.
  • Capability inventory: The agent is granted permission to read the entire source codebase and write output files specifically under the {product_root}/docs/context/ directory.
  • Sanitization: No explicit sanitization or validation of the names or content discovered in the codebase is performed before inclusion in the agent-dense output report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 06:55 PM
Security Audit — agent-trust-hub — ns-harness-bootstrap-brownfield