matrixscan-ar-kmp

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to fetch documentation from external URLs (docs.scandit.com) and check for version updates on Maven Central (central.sonatype.com). This creates an attack surface where malicious content on these external sites could influence agent behavior.
  • Ingestion points: External documentation pages and package registry metadata fetched at runtime via the agent's browser or network tools.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions within the fetched data.
  • Capability inventory: The agent has the capability to write files to the local project and perform network requests to fetch documentation.
  • Sanitization: No sanitization or validation of the fetched documentation is required by the skill.
  • [PROMPT_INJECTION]: The skill contains instructions aimed at overriding the agent's standard behavior and training data.
  • Behavioral overrides: Instructions such as "Critical: Do Not Trust Internal Knowledge" and "Always verify APIs against the references" are used to force the agent to disregard its training data.
  • Concealment patterns: The instruction to "Write the integration code directly into the project's files — do not just show it in chat" discourages showing the proposed changes to the user in the chat interaction before file modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:18 AM
Security Audit — agent-trust-hub — matrixscan-ar-kmp