hateoas

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and modify existing Java source code containing Spring HATEOAS models and controllers. This creates an indirect prompt injection surface where the agent's behavior could be influenced by malicious patterns or instructions embedded within the source code files it processes.
  • Ingestion points: The skill ingests project source code files identifying types such as EntityModel, CollectionModel, and RepresentationModel as specified in SKILL.md.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded code comments/instructions are defined to protect the agent context.
  • Capability inventory: The skill facilitates the generation and modification of Java source files and build configurations (Maven XML) for creating HATEOAS-compliant REST APIs, as shown in SKILL.md and templates/OrderModelAssembler.java.
  • Sanitization: No input sanitization or validation of the processed source code is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:46 AM
Security Audit — agent-trust-hub — hateoas