to-fuzz

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its processing of codebase content.
  • Ingestion points: Reads codebase and conversation history as defined in SKILL.md.
  • Boundary markers: None identified; it lacks delimiters to isolate untrusted code data from the agent's instruction set.
  • Capability inventory: The skill can write documentation and scaffold executable code stubs to the local repository.
  • Sanitization: There is no evidence of sanitization or filtering of the ingested content to prevent malicious instructions embedded in codebase comments or strings from being followed during the plan generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 06:17 PM
Security Audit — agent-trust-hub — to-fuzz