owasp-top10-analysis
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a workflow for auditing external web application components, which creates a potential surface for indirect prompt injection if the ingested files contain malicious instructions.
- Ingestion points: Source code, server configuration files, and application responses reviewed during the security assessment process (SKILL.md).
- Boundary markers: None; the instructions do not establish delimiters or require the agent to ignore instructions embedded within the audited content.
- Capability inventory: The agent is expected to use its default tools for file system access and data analysis to complete the audit tasks.
- Sanitization: The skill does not provide guidelines for escaping or validating external data before it is processed by the agent.
Audit Metadata