vercel-deployment
Fail
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill employs a reference-based grounding system that instructs the agent to treat
references/patterns.md,references/sharp_edges.md, andreferences/validations.mdas the primary sources of truth. While this is the intended design for providing expert domain knowledge, it creates a surface where the contents of these files could theoretically influence agent behavior beyond its base instructions.\n - Ingestion points:
references/patterns.md,references/sharp_edges.md, andreferences/validations.mdare loaded as context for the agent.\n - Boundary markers: The skill lacks explicit boundary markers or instructions to disregard potential commands found within the reference files, opting instead for strict grounding.\n
- Capability inventory: The agent provides architectural advice, code review, and validation based on the input files.\n
- Sanitization: No dynamic sanitization is applied to the reference content, as it is considered part of the skill's static knowledge base.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata