tdd
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read
AGENTS.mdfiles within the codebase to synchronize vocabulary and interface language. This establishes an ingestion point for untrusted data that could contain embedded instructions intended to influence the agent's behavior. - Ingestion points: Root-level and directory-specific
AGENTS.mdfiles (SKILL.md). - Boundary markers: The instructions do not specify any delimiters or protective prompts to isolate the content of
AGENTS.mdfrom the agent's operational logic. - Capability inventory: While the skill itself is instructional, it is designed to guide high-capability actions such as writing and modifying source code and tests.
- Sanitization: There are no instructions for the agent to validate or sanitize the content retrieved from these metadata files before adoption.
Audit Metadata