agentic-validators
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of repository content such as code, configuration files, and documentation through validation tools, creating a surface for indirect prompt injection.\n
- Ingestion points: Files within the repository environment are accessed and analyzed by the agent during the validation phases (SKILL.md).\n
- Boundary markers: The instructions do not define specific delimiters or 'ignore' instructions to isolate potentially untrusted file content from the agent's core instructions during the validation process.\n
- Capability inventory: The skill utilizes toolchains like 'eslint', 'ruff', and 'pytest' which involve subprocess execution on files (SKILL.md, references/HOOK_RECIPES.md).\n
- Sanitization: The instructions do not describe any sanitization or escaping mechanisms for the processed file content in the validator design.
Audit Metadata