agent-ingestor

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses directive language and strong imperatives such as 'MANDATORY', 'CRITICAL', and 'MUST'. These are used to enforce a strict security and architectural protocol for the agent's repository and do not attempt to bypass agent safety filters.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest untrusted data from external configuration folders and user-provided prompts, creating an attack surface for indirect injection.
  • Ingestion points: External configuration folders and user-provided text snippets are processed as input (SKILL.md).
  • Boundary markers: No specific delimiters or boundary markers are defined for the ingested data.
  • Capability inventory: The skill has the capability to modify repository configuration files across multiple directories (e.g., _core/, .cursor/, opencode/agents/).
  • Sanitization: The skill implements a 'Lexical Translation' phase that strips technical dialects and tool-specific commands from the input. Furthermore, a mandatory Human-In-The-Loop (HITL) step requires the user to approve all changes after reviewing a detailed plan and the proposed source code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 08:53 PM
Security Audit — agent-trust-hub — agent-ingestor