differential-audit

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill methodology involves reading and analyzing external codebases and data outputs, which creates an ingestion surface for potentially untrusted data.
  • Ingestion points: External code and data are ingested via the Read, Grep, and Glob tools during the audit process (referenced in Steps 2, 4, and 7 of SKILL.md).
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore embedded instructions' warnings for the agent when processing external file content.
  • Capability inventory: The agent has access to Bash and Write tools, which could theoretically be used to execute commands or modify the file system based on input from the audited content.
  • Sanitization: There are no explicit instructions for sanitizing or filtering content read from external implementations before it is processed in the audit context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 06:31 PM
Security Audit — agent-trust-hub — differential-audit