effect-ts
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and modify a user's local project environment, including source code, manifests, and lockfiles. This creates an attack surface where instructions embedded within the analyzed project files could potentially influence the agent's behavior.
- Ingestion points: The skill instructions direct the agent to resolve and inspect the target package manifest, lockfiles, and installed package source (SKILL.md, Evidence Order).
- Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions that may be contained within the code files being analyzed.
- Capability inventory: The agent is authorized to perform file read and write operations to implement coding changes (SKILL.md, Workflow).
- Sanitization: There are no explicit requirements for the agent to sanitize or validate external content before interpolating it into prompts or using it to drive decisions.
Audit Metadata