ponytail-audit
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is strictly limited to a passive auditing role. It contains explicit instructions that it should not apply any fixes or changes to the repository, serving as a safeguard against unauthorized modifications to the codebase based on the audit results.
- [NO_CODE]: The skill is implemented entirely through natural language instructions within the markdown body and metadata. It does not include any executable scripts, binary files, or dependencies on external software packages.
- [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection as it is instructed to scan the entire repository (untrusted data) without specific boundary markers or sanitization of the content it processes. However, this risk is mitigated by the fact that the agent's inventory of capabilities during the audit is limited to listing findings in a report, with no network or write operations allowed. Additionally, it includes a benign control command to revert to "normal mode" once the audit is complete.
Audit Metadata