dotnet-version-detection

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill executes dotnet --version at load time via the ! syntax in SKILL.md. This is used for environment detection and is hardcoded to a benign version check.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses untrusted workspace files to determine project versions, creating a vulnerability to indirect instructions.
  • Ingestion points: Processes .csproj, Directory.Build.props, and global.json files within the user's project directory.
  • Boundary markers: Lacks explicit delimiters or 'ignore embedded instructions' warnings for the content extracted from these project files.
  • Capability inventory: Provides detection and versioning context used by multiple downstream .NET development skills which may have file-system or network capabilities.
  • Sanitization: Does not provide evidence of validation or sanitization for metadata values (like TargetFramework or LangVersion) before they are interpolated into the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:31 AM
Security Audit — agent-trust-hub — dotnet-version-detection