skills/xfstudio/skills/c4-code/Gen Agent Trust Hub

c4-code

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to analyze and document external source code directories, which creates a surface for indirect prompt injection. Malicious instructions could be embedded in code comments or metadata of the files being analyzed. The instructions lack explicit boundary markers or guidance to ignore instructions found within the source code being documented.
  • Ingestion points: External source code files and directories (specified in SKILL.md).
  • Boundary markers: No delimiters or ignore-instructions warnings are provided.
  • Capability inventory: The skill relies on standard file reading and analysis capabilities.
  • Sanitization: No sanitization or validation of the analyzed code content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 03:02 AM
Security Audit — agent-trust-hub — c4-code