skills/withqwerty/nutmeg/nutmeg/Gen Agent Trust Hub

nutmeg

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting data from external and potentially untrusted sources while maintaining access to sensitive capabilities.\n
  • Ingestion points: The skill retrieves content from the internet via the WebFetch and WebSearch tools and reads local project files including .nutmeg.user.md, docs/entity-resolution-routing.md, and docs/accuracy-guardrail.md.\n
  • Boundary markers: The instructions lack explicit delimiters or specific warnings for the agent to treat data from these external or file-based sources as untrusted or to ignore embedded instructions.\n
  • Capability inventory: The skill is authorized to use powerful tools including Bash for command execution, Write for file modification, and Agent for delegating tasks to other specialized assistants.\n
  • Sanitization: There are no defined procedures for sanitizing, validating, or escaping content retrieved from web sources or project files before it influences agent routing logic or tool parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 03:24 PM
Security Audit — agent-trust-hub — nutmeg