explain

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external content such as source code, tests, and Git history, which can serve as a vector for indirect prompt injection.
  • Ingestion points: The agent is instructed in SKILL.md to gather full context by reading code, surrounding modules, tests, comments, and git history using tools like Read, Grep, and Glob.
  • Boundary markers: The instructions lack specific guidance on using delimiters or "ignore embedded instructions" warnings when handling content from external files.
  • Capability inventory: The skill is configured with access to Bash, Read, Grep, and Glob, providing a significant capability set if an injection were successful.
  • Sanitization: There are no requirements defined for sanitizing, escaping, or validating the content retrieved from the file system before the agent processes it for explanation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:22 PM
Security Audit — agent-trust-hub — explain