skills/quad4-software/ai/meshchatx/Gen Agent Trust Hub

meshchatx

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from MeshChatX documentation and GitHub issues through tools like search_docs and GitHub issue management functions. This creates a surface for indirect prompt injection if the fetched content contains instructions designed to influence the agent's behavior. However, this is an inherent risk for tools that interact with external content and the skill lacks dangerous autonomous capabilities that would escalate this risk.
  • Ingestion points: GitHub issue content, documentation pages.
  • Boundary markers: Not explicitly defined in the high-level description.
  • Capability inventory: Documentation search, code snapshotting (read-only), and GitHub issue creation/updates.
  • Sanitization: Not specified in the skill manifest.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:56 PM
Security Audit — agent-trust-hub — meshchatx