vercel-deployment

Fail

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill employs a reference-based grounding system that instructs the agent to treat references/patterns.md, references/sharp_edges.md, and references/validations.md as the primary sources of truth. While this is the intended design for providing expert domain knowledge, it creates a surface where the contents of these files could theoretically influence agent behavior beyond its base instructions.\n
  • Ingestion points: references/patterns.md, references/sharp_edges.md, and references/validations.md are loaded as context for the agent.\n
  • Boundary markers: The skill lacks explicit boundary markers or instructions to disregard potential commands found within the reference files, opting instead for strict grounding.\n
  • Capability inventory: The agent provides architectural advice, code review, and validation based on the input files.\n
  • Sanitization: No dynamic sanitization is applied to the reference content, as it is considered part of the skill's static knowledge base.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 26, 2026, 03:55 PM
Security Audit — agent-trust-hub — vercel-deployment