agent-config-audit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and analyzing untrusted workspace files (e.g.,
AGENTS.md,CLAUDE.md,.cursorrules). This creates an attack surface where malicious instructions embedded in those files could attempt to influence the agent's behavior during the audit process. - Ingestion points: The skill uses
globandgrepto scan numerous workspace configuration files as specified inSKILL.md(Step 1 and Step 2). - Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when reading these files.
- Capability inventory: The skill possesses file read/write capabilities (in
fixmode) and shell execution capabilities (glob,grep). - Sanitization: No specific sanitization or validation of the content of the audited files is described before it is processed or reported to the user.
Audit Metadata