green-gate

Fail

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: CRITICALPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes coverage/lcov.info to autonomously identify code areas for modification. This external file represents an indirect prompt injection surface where malicious data could influence the agent's code generation logic. 1. Ingestion points: coverage/lcov.info located in the package root. 2. Boundary markers: None specified for the parsing process. 3. Capability inventory: Edit, Write, and mcp__very-good-cli__test. 4. Sanitization: No validation is performed on data extracted from the coverage report before it influences code edits.
  • [COMMAND_EXECUTION]: The instructions permit using Bash to parse lcov.info. Unsanitized content from this file could potentially lead to command injection if the agent constructs shell commands (e.g., using grep or awk) using raw strings from the coverage file. The automated security alert regarding lcov.info being a malicious URL is likely a false positive where the scanner misidentified the file extension as a Top-Level Domain (TLD).
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 3, 2026, 09:42 PM
Security Audit — agent-trust-hub — green-gate