security-vuln-gauntlet

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for the agent to analyze external and potentially untrusted software artifacts, which creates a surface for indirect prompt injection attacks where malicious data in the target files could attempt to influence the agent's behavior.
  • Ingestion points: The skill instructs the agent to inspect source code, API responses, binary files, and cloud configurations across all domain checklists (references/checklists-by-domain.md).
  • Boundary markers: The methodology relies on a human-in-the-loop 'Validator' role and a 'Gauntlet Loop' process rather than technical delimiters or explicit 'ignore' instructions for the data being analyzed.
  • Capability inventory: The agent is directed to use its tools for file system access, network operations (specifically for canary/collaborator requests), and binary analysis.
  • Sanitization: The instructions focus on identifying security weaknesses in the target but do not specify technical sanitization or filtering for the data the agent itself processes during the review.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 10:50 PM
Security Audit — agent-trust-hub — security-vuln-gauntlet