skills/sarthib7/agentsmith/build/Gen Agent Trust Hub

build

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because its logic and planning are driven by the contents of external files, SPEC.md and FORMAT.md. Malicious instructions placed in these files by an external actor could override the agent's intended behavior.\n
  • Ingestion points: Reads task definitions, invariants, and interface definitions from SPEC.md and FORMAT.md in the project directory or fallback path.\n
  • Boundary markers: No boundary markers or explicit safety instructions are used to distinguish specification data from potential malicious commands embedded within the files.\n
  • Capability inventory: The skill possesses significant capabilities, including modifying source code, writing to documentation, executing shell commands for verification, performing git commits, and invoking other skills.\n
  • Sanitization: The skill does not perform any validation or sanitization on the content extracted from the specification files before using it to generate plans or code modifications.\n- [COMMAND_EXECUTION]: The skill executes a verification command (e.g., test, build, lint) defined during the planning phase. Because the task details and the verification requirements are sourced from an untrusted specification file, this process can be manipulated to execute unauthorized shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 08:20 AM
Security Audit — agent-trust-hub — build