secure-coding

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill resolves security standards by reading a .lattice/config.yaml file and additional Markdown files from the repository being analyzed.
  • Ingestion points: The skill reads .lattice/config.yaml and follows paths specified in paths.secure_coding and paths.language_idioms within the project root.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when loading project-specific configuration or idiom files.
  • Capability inventory: The skill influences code generation behavior and does not perform network operations, administrative file writes, or subprocess execution.
  • Sanitization: The instructions loaded from custom repository files are applied as overrides or overlays without validation or sanitization, potentially allowing repository-stored instructions to weaken security checks or redirect agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:13 PM
Security Audit — agent-trust-hub — secure-coding