performance-select-columns
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill instructs the agent to ingest data from the local environment while maintaining code execution capabilities.
- Ingestion points: The agent is directed to analyze the Laravel project's version, PHP version, package manager, and existing project conventions (SKILL.md).
- Boundary markers: No delimiters or instructions to ignore embedded directives in the analyzed project data are provided.
- Capability inventory: The workflow requires the agent to run targeted tests and quality checks, which involves executing shell commands via agent tools (SKILL.md).
- Sanitization: No sanitization or validation of project data is specified before processing.
- Mitigation: Wrap ingested project content in clear delimiters and add instructions for the agent to ignore any embedded directives within the analyzed files.
Audit Metadata