performance-select-columns

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill instructs the agent to ingest data from the local environment while maintaining code execution capabilities.
  • Ingestion points: The agent is directed to analyze the Laravel project's version, PHP version, package manager, and existing project conventions (SKILL.md).
  • Boundary markers: No delimiters or instructions to ignore embedded directives in the analyzed project data are provided.
  • Capability inventory: The workflow requires the agent to run targeted tests and quality checks, which involves executing shell commands via agent tools (SKILL.md).
  • Sanitization: No sanitization or validation of project data is specified before processing.
  • Mitigation: Wrap ingested project content in clear delimiters and add instructions for the agent to ignore any embedded directives within the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 02:32 PM
Security Audit — agent-trust-hub — performance-select-columns