explore-solutions

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is instructed to scan the repository codebase to find reusable logic and friction points, which brings untrusted data into the agent's context.
  • Ingestion points: The agent scans the current repository for models, classes, routes, controllers, and frontend components to match against requirements (SKILL.md).
  • Boundary markers: There are no instructions providing delimiters or 'ignore' warnings for instructions that might be embedded in the scanned code (e.g., inside comments or documentation strings).
  • Capability inventory: The skill has the ability to read all files in the repository and write a 'hand-off' file containing the exploration results to the local filesystem (SKILL.md).
  • Sanitization: No sanitization, validation, or filtering of the repository content is performed before the agent processes it to generate or compare solution ideas.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 09:30 AM
Security Audit — agent-trust-hub — explore-solutions