rent-burden

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to autonomously read and analyze a project's entire codebase, which introduces a potential surface for indirect prompt injection if the ingested files contain malicious instructions.
  • Ingestion points: Phase 1 (System Discovery) instructs the agent to read all project configuration and scan capabilities.
  • Boundary markers: The instructions lack explicit boundary markers or directives to ignore instructions embedded within the codebase being analyzed.
  • Capability inventory: The skill performs analysis and generates reports based on ingested data, though it includes explicit 'DO NOT' constraints against code modification or PII inclusion.
  • Sanitization: There are no explicit steps provided for sanitizing or validating the content of the external files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — rent-burden