deepinit

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads all files in a directory to analyze their purpose and generate documentation, creating a surface for indirect prompt injection if the files contain malicious instructions.
  • Ingestion points: The process described in 'Step 3: Generate Level by Level' involves reading all files in a directory to analyze purpose and relationships.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the processed files.
  • Capability inventory: The 'writer' subagent has the capability to perform filesystem writes to create AGENTS.md files.
  • Sanitization: The workflow does not include sanitization or validation of the content read from files before it is processed by the analysis agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:51 PM
Security Audit — agent-trust-hub — deepinit