sast-ssrf
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external codebase files, which provides a surface for indirect prompt injection where malicious code comments or strings could attempt to influence the agent's behavior.
- Ingestion points: The agent reads project source code files and architectural metadata.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands when the agent reads untrusted code content.
- Capability inventory: The agent has the capability to read and write files for report generation and to spawn parallel subagents for specialized tasks.
- Sanitization: No specific input sanitization or content filtering is defined for the codebase data being analyzed.
Audit Metadata