threat-patch
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data sources which could contain malicious instructions designed to influence the agent's behavior during code generation.\n
- Ingestion points: Findings are read from findings.json, Codex CSV files, and THREAT-MODEL.md as described in the Phase 1 workflow.\n
- Boundary markers: The skill lacks explicit negative constraints to ignore natural language instructions that might be embedded within the data fields of the ingested findings.\n
- Capability inventory: The skill has significant capabilities, including source code modification via Edit and Write tools and shell command execution for testing.\n
- Sanitization: Risk is reduced by mandatory user confirmation gates in the workflow and the use of PreToolUse hooks for oversight.\n- [COMMAND_EXECUTION]: The skill executes a local utility script to parse findings into a structured format.\n
- Evidence: The script scripts/parse-findings.sh is invoked to process CSV data using an embedded Python script.
Audit Metadata