render-disks

Warn

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill metadata identifies the author as "Render", which contradicts the provided author information ("Sarthib7"). This misattribution is deceptive and may lead users to trust the instructions based on a false claim of official origin.\n- [PROMPT_INJECTION]: The skill describes managing persistent storage for "file uploads" and "CMS media", which are common vectors for untrusted external data. If an agent processes data from these disk locations without using boundary markers or sanitization, it could be vulnerable to indirect prompt injection.\n
  • Ingestion points: The skill explicitly lists mount paths for persistent storage, such as /opt/render/project/src/uploads and /var/data (documented in SKILL.md).\n
  • Boundary markers: There are no instructions or best practices provided for the agent to use delimiters or ignore embedded instructions when reading from these storage locations.\n
  • Capability inventory: The skill documents administrative commands for file transfers (scp, wormhole) and configuration via blueprints, but does not include automated scripts that execute the data stored on disk.\n
  • Sanitization: The skill does not provide methods for validating or sanitizing the content stored on persistent disks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 1, 2026, 11:04 AM
Security Audit — agent-trust-hub — render-disks