effect-resource-management
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for handling external data which introduces a vulnerability surface.
- Ingestion points: Resource acquisition patterns in SKILL.md, such as
acquireFile(path),acquireConnection(config), andacquireWebSocket(url), accept external strings as input. - Boundary markers: The instructions lack explicit boundary markers or directives for the agent to disregard instructions potentially embedded within the data it processes.
- Capability inventory: The skill demonstrates capabilities including file system access (
fs.open,fs.readFile), database interaction (conn.query), and network connectivity (WebSocket) in SKILL.md. - Sanitization: The provided code templates do not include sanitization, validation, or escaping mechanisms for the external inputs they process.
Audit Metadata