component-usage-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for running shell commands including grep, find, awk, and sed. These are used to search for Twig include patterns and mock references within the src/components/ directory. These operations are appropriate for the skill's stated purpose of codebase analysis.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes content from local source files, which represents an indirect prompt injection surface. If an attacker can write to the project's Twig or YAML files, they could insert malicious instructions intended for the agent.\n
  • Ingestion points: Twig template files and YAML mock files located in src/components/.\n
  • Boundary markers: The analysis methodology does not specify any delimiters or ignore-instructions for the ingested content.\n
  • Capability inventory: The skill possesses the capability to read files and execute shell commands for searching.\n
  • Sanitization: There are no instructions to sanitize or validate the content of the files being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:21 PM
Security Audit — agent-trust-hub — component-usage-analysis