context-pack
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to have the agent ingest and process external repository data ("authoritative repo docs" and "task-specific evidence"). This ingestion process creates a potential surface for indirect prompt injection where malicious instructions hidden in the repository files could influence agent behavior.
- Ingestion points: Repository documentation and task-specific evidence files selected during the context-building process.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the gathered context.
- Capability inventory: The skill's stated purpose is reasoning and artifact generation; it does not explicitly request or utilize dangerous capabilities like network access or system modification.
- Sanitization: There are no specified mechanisms for filtering or sanitizing the content retrieved from the repository before processing.
Audit Metadata