instrument-tracking

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs an automated search for the WANIWANI_API_KEY within sensitive environment files such as .env and .env.local. Although the command uses grep -l to check for existence rather than exfiltrating content, the targeted access to these specific sensitive paths is noted as a data exposure risk.- [PROMPT_INJECTION]: This skill presents an indirect prompt injection surface (Category 8). It ingests untrusted data from project source code (ingestion points include src/, server/, lib/, and app/ directories) to perform mapping and instrumentation. There are no boundary markers or instructions to ignore embedded content during analysis. The agent possesses write capabilities and shell execution privileges (grep, bun run typecheck), which could be abused if malicious instructions are present in the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 03:19 PM
Security Audit — agent-trust-hub — instrument-tracking