guide-me

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted repository content, such as source code, git history, and documentation, to provide implementation guidance. This architectural pattern exposes the agent to potential instructions embedded within the codebase that could influence its behavior.\n
  • Ingestion points: The agent is directed to inspect files, search repositories, read git logs/diffs/status, and review documentation and compiler errors across the codebase.\n
  • Boundary markers: The instructions do not provide specific delimiters or instructions for the agent to disregard embedded commands in the files it analyzes.\n
  • Capability inventory: The agent has access to read-only investigative tools and verification commands (e.g., git, ripgrep, and test runners like pytest or npm test), but is explicitly prohibited from modifying, creating, or deleting implementation files.\n
  • Sanitization: The instructions do not specify any sanitization, validation, or filtering of the repository content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 01:32 PM
Security Audit — agent-trust-hub — guide-me