ai-engineer-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements systems designed to process untrusted external data, creating a potential vulnerability surface.
  • Ingestion points: The RAGSystem.ingest_documents method and AIAgent.run method in SKILL.md accept raw text data and user inputs for processing by LLMs.
  • Boundary markers: The provided Python snippets lack explicit boundary markers or system instructions designed to prevent the model from executing instructions embedded within the ingested documents.
  • Capability inventory: The skill is granted Bash(python:*), Write, and Edit tools, which could be misused if a prompt injection attack succeeds.
  • Sanitization: While the documentation mentions sanitization as a best practice, the implementation examples do not include logic for filtering or validating external content.
  • [DYNAMIC_EXECUTION]: The AI Agent implementation utilizes dynamic execution patterns to perform tasks.
  • Evidence: The AIAgent.execute_tool method in SKILL.md takes LLM-generated tool names and arguments, parsing them via json.loads and then executing them using Python's argument unpacking (**arguments) into function calls. This is a standard but dynamic execution pattern for agentic systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:41 PM
Security Audit — agent-trust-hub — ai-engineer-expert