astro-adversary-purple

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from pull requests, repository content, and team reports. It effectively mitigates potential injection attacks by instructing the agent to treat this data as "evidence, not instructions."
  • Ingestion points: Pull request text, repository content, and third-party reports (specified in SKILL.md).
  • Boundary markers: The skill provides a clear logical boundary by instructing the agent to ignore instructions embedded in the analyzed data.
  • Capability inventory: The skill allows the agent to read repository files and reference other internal developer skills.
  • Sanitization: The skill relies on the agent following its high-level instructional "contract" to ignore directives within the evidence.
  • [COMMAND_EXECUTION]: The instructions reference the use of pnpm lint:ai to verify code changes. This is a standard and expected development command within the Astro project's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:15 PM
Security Audit — agent-trust-hub — astro-adversary-purple