sast-config
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill operates by discovering and analyzing external configuration files and custom SAST rules. This ingestion of untrusted data creates a surface for indirect prompt injection, where malicious instructions could be embedded in fields such as rule messages or descriptions. The skill proactively addresses this by including a 'Prompt Injection Safety Notice' that instructs the agent to treat all analyzed content as data and to ignore any commands found within those files.
Audit Metadata