rspack-api-assessment
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, including GitHub Pull Requests, issues, and code search results, creating an attack surface for indirect prompt injection.
- Ingestion points:
SKILL.mddirects the agent to 'Accept a PR, issue, commit, symbol, or design proposal' and 'search current public GitHub code'. - Boundary markers: The instructions lack specific directives to use delimiters or explicitly ignore instructions embedded within the external data being analyzed.
- Capability inventory: The skill relies on the
gh(GitHub) CLI, local filesystem access, and Git history commands. - Sanitization: There are no instructions for sanitizing or filtering untrusted external content before it is interpolated into the agent's context for evaluation.
Audit Metadata