build-chatgpt-app
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill allows the agent to read and modify project files from external repositories, which is a potential surface for indirect instructions embedded in third-party code. \n
- Ingestion points: The workflow involves inspecting and refactoring project files from target repositories (SKILL.md). \n
- Boundary markers: The instructions do not define specific delimiters or "ignore" markers for external code content. \n
- Capability inventory: The skill generates code, scaffolds repo structures, and registers MCP server resources. \n
- Sanitization: The skill relies on the agent's built-in safety filters when processing project content. \n- [Credential Management Practice]: The skill references a practice of using a platform API key tool before implementation. \n
- Context: This is a standard approach for managing credentials in the developer ecosystem and aligns with official vendor recommendations for secure API access.
Audit Metadata