code-explanation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-specified source code, architecture, or system files (
[target]) which introduces an indirect prompt injection vulnerability surface if the analyzed files contain malicious instructions targeting the agent. - Ingestion points: Codebase components and files read via
Read/Grep/Globtools or via theExploresubagent as described inreferences/explain.md. - Boundary markers: Absent; there are no explicit instructions or structural delimiters defined to isolate the target code contents or tell the model to ignore any embedded prompt directives inside the processed files.
- Capability inventory: File system read tools (
Read/Grep/Glob), file creation/modification tools (Write,TodoWrite), and subagent orchestration via theTasktool. - Sanitization: There are no preprocessing, escaping, or verification steps mentioned to filter out natural language instructions embedded within comments or documentation strings of the target code.
Audit Metadata