audit-controls

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from project documents and lacks boundary markers or sanitization logic to prevent embedded instructions from influencing agent behavior.
  • Ingestion points: Internal legal and project documents are reviewed in Step 1.
  • Boundary markers: The instructions do not define delimiters or specific "ignore instructions" directives for the processed data.
  • Capability inventory: The skill utilizes Bash, Write, and WebFetch tools, providing a path for command execution or data exfiltration if triggered by malicious input.
  • Sanitization: No input validation or sanitization of project files is specified.
  • [COMMAND_EXECUTION]: The skill includes Bash in its allowed-tools list. While intended for legal review tasks, this tool provides a high-privilege interface to the underlying system that could be abused if the agent is compromised via indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:49 AM
Security Audit — agent-trust-hub — audit-controls