app-design
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from existing codebases (source code, documentation, and manifests) which could contain malicious instructions targeted at the agent.\n
- Ingestion points: Files are read using the
readandgreptools during the Discovery phase inreferences/existing-project.md.\n - Boundary markers: The instructions do not specify the use of delimiters or explicit 'ignore instructions' warnings when processing external file content.\n
- Capability inventory: The skill has significant capabilities, including shell access via
bashfor running builds and tests, as well aswriteandeditfor modifying the filesystem.\n - Sanitization: There is no automated sanitization or filtering of the content ingested from the audited project files, relying instead on manual user verification steps.
Audit Metadata