validate-agent
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of plan content to validate technical choices.
- Ingestion points: The agent receives 'Plan content' (SKILL.md) to extract technical choices for validation.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the plan content as data rather than instructions or to ignore embedded instructions within the plan.
- Capability inventory: The skill can execute local Python scripts, perform web searches, and write validation reports to the file system.
- Sanitization: There is no mention of sanitizing or validating the extracted technical choices before they are used in search queries or reports.
- [COMMAND_EXECUTION]: The skill executes a local Python script to analyze past precedents.
- Evidence: The skill runs
uv run python scripts/braintrust_analyze.py --rag-judge --plan-file <plan-path>to perform a precedent check based on the provided plan file.
Audit Metadata