setup

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. It is designed to ingest and analyze untrusted data from the local repository, including documentation files, commit messages, and issue tracker templates. This information is used to settle facts and guide a setup interview that determines the behavior and configuration of other AI agent skills.
  • Ingestion points: Processes repository files such as package.json, AGENTS.md, CLAUDE.md, .cursor/rules, CONTEXT.md, design docs, and .github/ templates.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded malicious content are present when processing repository data.
  • Capability inventory: Performs file system writes to create the config doc and invokes subsequent engine skills.
  • Sanitization: No sanitization or validation of the processed external repository content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 03:34 PM
Security Audit — agent-trust-hub — setup