skills/taecontrol/skills/agents-md/Gen Agent Trust Hub

agents-md

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection attack surface as it is designed to ingest and process external project files that may contain untrusted content. 1. Ingestion points: Project files including README, ADRs, product vision, and source code as identified in SKILL.md. 2. Boundary markers: No specific delimiters or instructions to ignore embedded commands were found in the ingestion logic. 3. Capability inventory: The skill possesses file system read and write capabilities to audit and update local instruction files. 4. Sanitization: No explicit content sanitization or validation routines are described.
  • [SAFE]: The skill follows documentation best practices and does not contain any patterns associated with obfuscation, privilege escalation, or persistence. All external resources and logic are consistent with the vendor's stated purpose of managing project instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 11:54 PM
Security Audit — agent-trust-hub — agents-md