queue-recon
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted external data (queue configurations and consumer code) while maintaining powerful capabilities.
- Ingestion points: The agent reads external queue configurations, consumer source code, and monitoring setups in Step 1.
- Boundary markers: There are no explicit instructions or delimiters used to separate the analyzed content from the agent's instructions, nor are there warnings to ignore embedded commands within the analyzed files.
- Capability inventory: The skill has access to potentially dangerous tools including
Bash,Write,WebFetch, andReadacross its operations. - Sanitization: There is no evidence of validation or sanitization of the content read from the local files or external sources before it is processed by the agent.
Audit Metadata