threat-patch

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data sources which could contain malicious instructions designed to influence the agent's behavior during code generation.\n
  • Ingestion points: Findings are read from findings.json, Codex CSV files, and THREAT-MODEL.md as described in the Phase 1 workflow.\n
  • Boundary markers: The skill lacks explicit negative constraints to ignore natural language instructions that might be embedded within the data fields of the ingested findings.\n
  • Capability inventory: The skill has significant capabilities, including source code modification via Edit and Write tools and shell command execution for testing.\n
  • Sanitization: Risk is reduced by mandatory user confirmation gates in the workflow and the use of PreToolUse hooks for oversight.\n- [COMMAND_EXECUTION]: The skill executes a local utility script to parse findings into a structured format.\n
  • Evidence: The script scripts/parse-findings.sh is invoked to process CSV data using an embedded Python script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — threat-patch