maintain-agentic-system
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface (Category 8) because it processes repository content to update its instructions. \n- Ingestion points: The skill reads repository-local files including instructions, prompts, and knowledge docs during the 'Gate 2' scan. \n- Boundary markers: It strictly excludes 'session-folder contents' but lacks explicit markers for instructions within the maintained files. \n- Capability inventory: It can read repository files, utilize hidden subagents, and modify instructions upon approval. \n- Sanitization: No explicit sanitization or escaping of scanned repository content is performed before processing.
Audit Metadata