green-gate
Fail
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: CRITICALPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes
coverage/lcov.infoto autonomously identify code areas for modification. This external file represents an indirect prompt injection surface where malicious data could influence the agent's code generation logic. 1. Ingestion points:coverage/lcov.infolocated in the package root. 2. Boundary markers: None specified for the parsing process. 3. Capability inventory:Edit,Write, andmcp__very-good-cli__test. 4. Sanitization: No validation is performed on data extracted from the coverage report before it influences code edits. - [COMMAND_EXECUTION]: The instructions permit using Bash to parse
lcov.info. Unsanitized content from this file could potentially lead to command injection if the agent constructs shell commands (e.g., usinggreporawk) using raw strings from the coverage file. The automated security alert regardinglcov.infobeing a malicious URL is likely a false positive where the scanner misidentified the file extension as a Top-Level Domain (TLD).
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata