proof-of-work
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and display content from local files to verify implementation success, creating an attack surface where malicious data could influence agent behavior.\n
- Ingestion points: Verification steps using
Read,cat,head, andgit diffon potentially untrusted or externally modified files.\n - Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' directives for the content being verified.\n
- Capability inventory: The skill has access to powerful tools including
Bashfor command execution andWrite/Editfor file system modifications.\n - Sanitization: Content is read and presented directly into the agent's context without any filtering, escaping, or validation logic.
Audit Metadata