funstack-static-knowledge

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides architectural information and configuration examples for the Funstack Static framework. It is intended for developer assistance and contains no malicious instructions or executable code.
  • [PROMPT_INJECTION]: The skill directs the agent to read documentation from a local package path (node_modules/@funstack/static/dist/docs/index.md). This constitutes an indirect prompt injection surface as the agent is instructed to ingest content from an external source.
  • Ingestion points: The file path node_modules/@funstack/static/dist/docs/index.md mentioned in SKILL.md.
  • Boundary markers: Absent. There are no instructions provided to the agent to delimit or verify the content of the documentation file.
  • Capability inventory: None. The skill does not define any tools, scripts, or subprocess executions.
  • Sanitization: Absent. Content from the documentation file is intended to be read directly by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 03:56 PM