cudaq-guide

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read local files to provide answers, creating a surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: The agent is directed in SKILL.md to "Read local CUDA-Q documentation files" and uses Glob and Read tools based on the documentation map in references/onboarding.md.
  • Boundary markers: The instructions in SKILL.md do not provide delimiters or "ignore embedded instructions" warnings for processing external file content.
  • Capability inventory: The skill manifest SKILL.md allows the Read, Glob, and Grep tools. No file-write, executable scripts, or network capabilities are included in the skill.
  • Sanitization: There are no sanitization or filtering steps defined in SKILL.md for processing the content of local documentation files.
  • [DYNAMIC_EXECUTION]: The references/authoring.md file provides a code pattern for "Variable-shape return lists" that uses compile() and exec() to dynamically generate kernels. While this is documented as a legitimate way to handle framework constraints in the user's Python environment, it encourages the use of dynamic execution patterns.
  • [NO_CODE]: The skill does not include any executable scripts, binaries, or automation components; it functions exclusively as an instructional resource for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:29 PM
Security Audit — agent-trust-hub — cudaq-guide