schemasmash
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits arbitrary codebase files, which provides a surface for indirect prompt injection if the files contain malicious instructions disguised as data.
- Ingestion points: Project codebase files including source code, database schemas, and serialization shapes.
- Boundary markers: No explicit delimiters are used for ingested data.
- Capability inventory: Restricted to read-only inspection and sub-agent orchestration.
- Sanitization: Requires manual verification of findings by the coordinator agent to reduce reliance on potentially poisoned inputs.
Audit Metadata