seatbelt-sandboxer
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references external documentation and sample project data from public repositories for testing purposes.
- Evidence: Mentions using sample inputs from the
rstackjs/rstack-examplesrepository on GitHub and refers to documentation atreverse.put.asandkeith.github.io. - [INDIRECT_PROMPT_INJECTION]: The skill methodology involves processing external sample data to validate sandbox configurations, which introduces a surface for indirect prompt injection if the processed content contains malicious instructions.
- Ingestion points: The documentation in
SKILL.mdsuggests fetching example projects from external GitHub repositories during the testing phase. - Boundary markers: No specific boundary markers or instructions to ignore embedded commands are defined for the external test data.
- Capability inventory: The skill has access to the
Bashtool to executesandbox-execand theWritetool to create configuration files. - Sanitization: There is no explicit sanitization step mentioned for external content before it is used within the profiling or testing workflow.
Audit Metadata