research
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from primary sources (official docs, source code, specs) which can serve as a vector for indirect prompt injection.
- Ingestion points: The agent is instructed to investigate official documentation, source code, and APIs (SKILL.md).
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the external data are present.
- Capability inventory: The agent has the capability to write Markdown files to the repository based on the gathered information (SKILL.md).
- Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external sources before it is written to the repository.
Audit Metadata