cudaq-guide
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read local files to provide answers, creating a surface for indirect prompt injection if those files contain malicious instructions.
- Ingestion points: The agent is directed in
SKILL.mdto "Read local CUDA-Q documentation files" and usesGlobandReadtools based on the documentation map inreferences/onboarding.md. - Boundary markers: The instructions in
SKILL.mddo not provide delimiters or "ignore embedded instructions" warnings for processing external file content. - Capability inventory: The skill manifest
SKILL.mdallows theRead,Glob, andGreptools. No file-write, executable scripts, or network capabilities are included in the skill. - Sanitization: There are no sanitization or filtering steps defined in
SKILL.mdfor processing the content of local documentation files. - [DYNAMIC_EXECUTION]: The
references/authoring.mdfile provides a code pattern for "Variable-shape return lists" that usescompile()andexec()to dynamically generate kernels. While this is documented as a legitimate way to handle framework constraints in the user's Python environment, it encourages the use of dynamic execution patterns. - [NO_CODE]: The skill does not include any executable scripts, binaries, or automation components; it functions exclusively as an instructional resource for the agent.
Audit Metadata