audit-context-building

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains detailed instructions that direct the agent's internal reasoning process and analysis format. It enforces specific methodologies such as 'First Principles' and '5 Whys' while explicitly instructing the agent to suppress vulnerability detection and fix recommendations during the context-building phase to avoid premature conclusions.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a framework for the agent to ingest and analyze untrusted third-party code provided during a security audit.
  • Ingestion points: The agent is directed to analyze logic blocks, external call parameters, return values, and state variables within provided source code.
  • Boundary markers: The instructions emphasize line-by-line analysis and require citations to the source material to maintain grounding, although no specific structural delimiters for the untrusted content are defined.
  • Capability inventory: The skill references the delegation of complex analysis tasks to a specific subagent named function-analyzer.
  • Sanitization: No explicit sanitization or filtering of the audited code is implemented, as the skill's purpose is to analyze the raw behavior of that code.
  • [COMMAND_EXECUTION]: The skill mentions the usage of platform-specific subagents (function-analyzer) to assist in complex data-flow or control-flow analysis tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 02:44 PM
Security Audit — agent-trust-hub — audit-context-building