spring-security

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including Spring configuration files and Java source code, which creates a potential surface for indirect prompt injection.
  • Ingestion points: The skill triggers on user-provided questions, pull requests, application.yml files, and Spring Security beans.
  • Boundary markers: The instructions do not define specific delimiters or guardrails to isolate untrusted user data from the agent's internal instructions.
  • Capability inventory: The skill consists solely of markdown instructions and does not include any executable scripts, network-active tools, or file-writing capabilities.
  • Sanitization: No input validation or sanitization routines are specified for the ingested content.
  • [SAFE]: The skill provides legitimate security review guidance and references well-known, trusted organizations for documentation, including Spring.io, OWASP, and NIST. All external references are informative and do not involve remote code execution or unauthorized downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 08:42 PM
Security Audit — agent-trust-hub — spring-security