clerk-validator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a vulnerability surface by ingesting and processing untrusted data from a project's local file system (source code, package manifests, and environment variables) to perform its validation tasks.
  • Ingestion points: Project files and directory structures scanned by the validate.py script via the --root parameter.
  • Boundary markers: No explicit delimiters or instructions are documented to prevent the agent from following commands embedded within the data it is analyzing.
  • Capability inventory: The skill utilizes Python-based file system access to read and verify project configurations.
  • Sanitization: The documentation does not specify any sanitization or escaping mechanisms for the project content being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:09 AM
Security Audit — agent-trust-hub — clerk-validator