zero-trust-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's reference implementations process untrusted data sources, including authentication headers and context-aware request objects, which presents an attack surface for indirect prompt injection.
  • Ingestion points: External data is ingested through Flask request objects, specifically in the /api/login and /api/protected endpoints, and the AccessRequest data structure in references/EXAMPLES.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between data and instructions within the processed objects.
  • Capability inventory: The skill configuration in SKILL.md allows the use of the Bash, Write, and Edit tools, which could be misused if the agent is influenced by malicious instructions in the input data.
  • Sanitization: The reference code uses mock logic that lacks input sanitization or verification of the data's integrity before it is used in decision-making logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — zero-trust-expert