spec-to-code-compliance

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external content such as protocol whitepapers, Notion exports, meeting transcripts, and source code. A malicious specification could attempt to influence the agent's audit findings through embedded instructions.\n- [INDIRECT_PROMPT_INJECTION]: Ingestion points: Data is ingested in Phase 0 and Phase 3 from external files including whitepaper.pdf, Protocol.md, and the smart contract codebase.\n- [INDIRECT_PROMPT_INJECTION]: Boundary markers: The instructions employ a structured 7-phase analysis process and require mandatory citation of exact evidence (quotes and line numbers) to ground the agent's reasoning.\n- [INDIRECT_PROMPT_INJECTION]: Capability inventory: The skill performs analytical tasks and generates audit reports; there are no instructions for network exfiltration, subprocess execution, or modification of security settings.\n- [INDIRECT_PROMPT_INJECTION]: Sanitization: Phase 1 includes a normalization process to strip layout noise and styling artifacts from various document formats (PDF, HTML, etc.) before they are analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:02 AM
Security Audit — agent-trust-hub — spec-to-code-compliance