cloak
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted external data, creating a surface for potential instruction injection during its analysis phases.
- Ingestion points: The
Alwayssection inSKILL.mdrequires the agent to scan code, configurations, logs, and database schemas for PII exposure, which are often provided by external or untrusted users. - Boundary markers: The instructions do not specify the use of boundary markers or delimiters to isolate processed data from the agent's control logic, nor is there explicit instruction to ignore embedded directives in the content being analyzed.
- Capability inventory: The skill is designed to provide actionable code remediation, facilitate DPIAs, and generate data flow diagrams, and it can hand off findings to other agents like
BuilderorSchema. - Sanitization: Although the skill requires redaction of PII in its output, it does not define mechanisms to sanitize or escape instructions that may be present in the source files being scanned.
Audit Metadata