injection

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The file 'references/payloads.md' contains strings designed to override LLM behavior, such as 'Ignore previous instructions', 'reveal the system prompt', and 'You are now in developer mode'. These are provided as test cases for LLM security auditing but exist within the skill's context and are readable by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes a payload library containing malicious instructions for testing purposes. \n
  • Ingestion points: 'references/payloads.md' \n
  • Boundary markers: Payloads are contained within markdown code blocks. \n
  • Capability inventory: The skill documentation describes shell command execution and security tool usage (Bandit, OWASP ZAP) as part of the auditing workflow. \n
  • Sanitization: None provided for the reference payload data.
  • [COMMAND_EXECUTION]: The skill provides multiple examples of shell command execution using 'os.system', 'os.popen', and 'subprocess' to demonstrate both vulnerable and safe coding practices. It also includes instructions for running external security tools via the command line.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:15 PM
Security Audit — agent-trust-hub — injection