context-pack

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to have the agent ingest and process external repository data ("authoritative repo docs" and "task-specific evidence"). This ingestion process creates a potential surface for indirect prompt injection where malicious instructions hidden in the repository files could influence agent behavior.
  • Ingestion points: Repository documentation and task-specific evidence files selected during the context-building process.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the gathered context.
  • Capability inventory: The skill's stated purpose is reasoning and artifact generation; it does not explicitly request or utilize dangerous capabilities like network access or system modification.
  • Sanitization: There are no specified mechanisms for filtering or sanitizing the content retrieved from the repository before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:00 AM
Security Audit — agent-trust-hub — context-pack