offensive-programming
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and follow repository-specific rules from
AGENTS.mdand linked files. This exposes the agent to potentially untrusted instructions embedded in repository data.\n - Ingestion points: The
AGENTS.mdfile at the repository root and any documents it references.\n - Boundary markers: Absent. The skill does not provide specific delimiters or instructions for the agent to isolate these external rules from its primary instructions.\n
- Capability inventory: The agent applies these rules to influence its code writing, state validation, and system logic decisions.\n
- Sanitization: Absent. The skill provides no mechanisms or instructions for the agent to validate or filter the content of the metadata files before following them.
Audit Metadata