explain
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external content such as source code, tests, and Git history, which can serve as a vector for indirect prompt injection.
- Ingestion points: The agent is instructed in
SKILL.mdto gather full context by reading code, surrounding modules, tests, comments, and git history using tools likeRead,Grep, andGlob. - Boundary markers: The instructions lack specific guidance on using delimiters or "ignore embedded instructions" warnings when handling content from external files.
- Capability inventory: The skill is configured with access to
Bash,Read,Grep, andGlob, providing a significant capability set if an injection were successful. - Sanitization: There are no requirements defined for sanitizing, escaping, or validating the content retrieved from the file system before the agent processes it for explanation.
Audit Metadata