gtm

Warn

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill functions as a stub, instructing the agent to load its primary logic from a local file path (~/Developer/Ankit Mishra AI/gtm/SKILL.md). This results in the agent's behavior being controlled by external content not subject to the initial analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local project files. Ingestion points: Project context files in ~/Developer/Ankit Mishra AI/gtm/projects/. Boundary markers: None specified to prevent embedded instructions in project data from influencing agent behavior. Capability inventory: The skill primarily uses file read capabilities to load instructions and data. Sanitization: No evidence of sanitization or validation of the externally loaded files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 5, 2026, 10:42 AM
Security Audit — agent-trust-hub — gtm