cite-recon
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill involves an inherent attack surface for indirect prompt injection due to its requirement to process external data.
- Ingestion points: In Step 1 (Gather Context), the skill utilizes 'WebSearch' and 'WebFetch' to collect regulatory guidance and reads existing project documents.
- Boundary markers: The instructions do not provide explicit delimiters or instructions to ignore embedded commands within the fetched data.
- Capability inventory: The skill manifest allows access to 'Bash', 'Write', and 'WebFetch' tools.
- Sanitization: There is no instruction for the agent to validate or sanitize external content before processing.
- [NO_CODE]: The skill consists entirely of natural language instructions and does not include any executable scripts or binary files.
Audit Metadata