add-javadoc

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process Java source files, which constitutes an ingestion point for potentially untrusted data. If these files contain malicious comments, they could attempt to influence the agent's behavior.
  • Ingestion points: Java source files (SKILL.md).
  • Boundary markers: None (the skill does not define delimiters to separate code from instructions).
  • Capability inventory: The agent uses its internal file-editing tools to modify source code.
  • Sanitization: No validation or sanitization of the input files is specified.
  • [NO_CODE]: The skill consists entirely of markdown documentation and instructions for the agent; no executable code or scripts are included.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — add-javadoc