attack-path-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and analyze external security scan findings, which could potentially contain malicious payloads or instructions aimed at influencing the agent's reasoning.
  • Ingestion points: The skill retrieves threat models and security candidates from artifact locations, such as ../../references/scan-artifacts.md and candidate lists.
  • Boundary markers: The skill does not explicitly define structural delimiters for the data it processes, instead relying on instructional logic to maintain analysis focus.
  • Capability inventory: The skill utilizes tools like list_codex_security_candidates and record_candidate_attack_paths to interact with scan data and record analysis outcomes.
  • Sanitization: The skill emphasizes rigorous validation through counterevidence checklists and severity policy calibration, which acts as a logical control when processing potentially untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 09:35 AM
Security Audit — agent-trust-hub — attack-path-analysis