ai-coding-agents-tools
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for tool runtimes that ingest data from external sources, which represents a structural attack surface for indirect prompt injection. * Ingestion points: The design includes processing remote SDK messages via a message adapter and injecting LSP diagnostics into the prompt after file edits (SKILL.md, references/deferred-loading-execution-and-remote-results.md). * Boundary markers: The guidance suggests using a normalized message model, but does not explicitly specify mandatory delimiters or 'ignore' instructions for untrusted external content. * Capability inventory: The proposed runtime supports powerful tools including shell execution (Bash), file system writes (Edit/Write), and network access (WebFetch). * Sanitization: Explicit sanitization or escaping of tool results prior to prompt interpolation is not detailed in the architectural patterns provided.
- [EXTERNAL_DOWNLOADS]: The skill provides references to official documentation and source code repositories for agent development. * Evidence: Links to Anthropics (code.claude.com, github.com/anthropics), OpenAI (openai.com, github.com/openai), and the Model Context Protocol (modelcontextprotocol.io) are used for implementation guidance and version tracking.
Audit Metadata