differential-audit
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill methodology involves reading and analyzing external codebases and data outputs, which creates an ingestion surface for potentially untrusted data.
- Ingestion points: External code and data are ingested via the Read, Grep, and Glob tools during the audit process (referenced in Steps 2, 4, and 7 of SKILL.md).
- Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore embedded instructions' warnings for the agent when processing external file content.
- Capability inventory: The agent has access to Bash and Write tools, which could theoretically be used to execute commands or modify the file system based on input from the audited content.
- Sanitization: There are no explicit instructions for sanitizing or filtering content read from external implementations before it is processed in the audit context.
Audit Metadata