config-hardener
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits user-provided configuration files, which creates a surface for indirect prompt injection where malicious instructions could attempt to manipulate the auditor's findings.\n- Ingestion points: Audits local configuration files including AGENTS.md and gateway/sandbox settings as defined in the SKILL.md instructions.\n- Boundary markers: Absent; there are no instructions to use delimiters or to ignore embedded directives within the audited data.\n- Capability inventory: The skill utilizes file-read and file-write permissions to perform audits and generate hardened configurations.\n- Sanitization: Absent; the content of the configuration files is processed without explicit escaping or sanitization to prevent injection.
Audit Metadata