build-chatgpt-app

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill allows the agent to read and modify project files from external repositories, which is a potential surface for indirect instructions embedded in third-party code. \n
  • Ingestion points: The workflow involves inspecting and refactoring project files from target repositories (SKILL.md). \n
  • Boundary markers: The instructions do not define specific delimiters or "ignore" markers for external code content. \n
  • Capability inventory: The skill generates code, scaffolds repo structures, and registers MCP server resources. \n
  • Sanitization: The skill relies on the agent's built-in safety filters when processing project content. \n- [Credential Management Practice]: The skill references a practice of using a platform API key tool before implementation. \n
  • Context: This is a standard approach for managing credentials in the developer ecosystem and aligns with official vendor recommendations for secure API access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:58 PM
Security Audit — agent-trust-hub — build-chatgpt-app