trailmark-finding-triage

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external security reports, SARIF results, and code annotations which are potentially untrusted. While this presents an indirect prompt injection surface, the skill includes explicit instructions to normalize inputs, verify anchors in code, and treat findings as 'candidates' rather than 'confirmed vulnerabilities,' which effectively manages the risk.
  • [DYNAMIC_EXECUTION]: The skill uses Python code templates to interact with the Trailmark Query Engine. The agent is instructed to populate these templates with parameters like directory paths and node IDs to perform graph analysis. This is a standard and necessary part of the tool's functionality for code analysis and is considered safe within this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:01 AM
Security Audit — agent-trust-hub — trailmark-finding-triage