spring-security
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including Spring configuration files and Java source code, which creates a potential surface for indirect prompt injection.
- Ingestion points: The skill triggers on user-provided questions, pull requests,
application.ymlfiles, and Spring Security beans. - Boundary markers: The instructions do not define specific delimiters or guardrails to isolate untrusted user data from the agent's internal instructions.
- Capability inventory: The skill consists solely of markdown instructions and does not include any executable scripts, network-active tools, or file-writing capabilities.
- Sanitization: No input validation or sanitization routines are specified for the ingested content.
- [SAFE]: The skill provides legitimate security review guidance and references well-known, trusted organizations for documentation, including Spring.io, OWASP, and NIST. All external references are informative and do not involve remote code execution or unauthorized downloads.
Audit Metadata