skills/slantview/claude/csharp-pro/Gen Agent Trust Hub

csharp-pro

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, including NuGet package documentation and existing workspace source code. Combined with its ability to write files and execute shell commands, this creates an attack surface for indirect prompt injection where malicious instructions embedded in data could influence agent behavior.
  • Ingestion points: The skill reads existing project files via Read, Glob, and Grep tools, and fetches external documentation and examples using Context7 MCP tools.
  • Boundary markers: None defined. The instructions do not specify the use of delimiters or 'ignore' instructions for the data being processed.
  • Capability inventory: Significant capabilities are enabled, including filesystem modification (Write, Edit, MultiEdit) and shell command execution (Bash).
  • Sanitization: No sanitization or validation steps are instructed for content fetched from external documentation services or libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 10:16 AM
Security Audit — agent-trust-hub — csharp-pro