ms-access-vcs

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by reading, analyzing, and editing external source files, including VBA modules (.cls), layout files (.bas), SQL queries (.sql), and configuration files (.json, .xml). These files represent untrusted ingestion points where malicious instructions could be embedded to influence the agent's behavior during the editing process.
  • Ingestion points: Files in the forms/, reports/, queries/, modules/, tbldefs/, and relations/ directories.
  • Boundary markers: The instructions do not specify explicit boundary markers or sanitization protocols for content read from these files.
  • Capability inventory: The skill allows for file system writing and modification of database structures and application logic.
  • Sanitization: The focus is on structural and format integrity (e.g., TabIndex contiguity, BOM preservation) rather than content sanitization for malicious prompts.
  • [COMMAND_EXECUTION]: The documentation instructs the agent to use shell commands such as printf to create new files with specific byte-order marks (printf '\xEF\xBB\xBF...' > path/to/file) and od to verify file encoding (od -c -N 5). These are legitimate and necessary actions for maintaining the specific file formats required by the Access VCS tool.
  • [DYNAMIC_EXECUTION]: The references/images.md file provides Python code snippets for hex-encoding image data and converting between image formats (PNG to BMP). These are intended as logic templates for the agent to follow when performing image-related tasks within the database source files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 05:20 AM