threat-model
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Data Ingestion and Processing: The skill is designed to ingest and analyze repository contents and security policies. While processing external data is a potential vector for indirect prompt injection, the instructions include specific guardrails to treat such content strictly as data for analysis, preventing it from influencing the agent's operational logic.
- Internal Capability Management: The skill manages threat model data using designated reference paths and caching mechanisms. The process involves verification steps for model scope and evidence, ensuring that the generated output remains consistent with the repository's actual architecture.
Audit Metadata