cto

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by instructing the agent to ingest and act upon data from external sources and workspace configuration files without explicit sanitization or boundary markers.
  • Ingestion points: Technical data and constraints are read from internal workspace files (context.md, operator.md, ai-landscape). Additionally, the agent is directed to perform live web searches and consult external provider documentation to verify technical specifications and pricing.
  • Boundary markers: The instructions do not define specific delimiters or provide guidance for the agent to ignore potentially malicious instructions embedded in these external data sources.
  • Capability inventory: The skill is designed for agents with file-reading capabilities and access to web search tools.
  • Sanitization: There are no requirements for validating, escaping, or filtering content retrieved from the web before it is processed by the agent.
  • [NO_CODE]: The skill consists entirely of instructional text and configuration metadata. It does not contain any executable scripts, binary files, or automated installation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 06:36 PM
Security Audit — agent-trust-hub — cto