analyze

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses the {{ARGUMENTS}} template tag to interpolate user-provided tasks directly into the instruction set. An attacker could provide input designed to override the skill's core instructions, such as the 'Read-Only' constraint.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external, potentially untrusted repository data including code, configuration, and documentation.
  • Ingestion points: Files, tests, configs, and docs from the target repository being analyzed in SKILL.md.
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore malicious commands embedded within the analyzed file content, relying instead on the agent's general persona and the specific 'Read-Only' instructions.
  • Capability inventory: The skill instructs the agent to read file paths and contracts. It specifically forbids editing files or running implementations, which serves as a significant mitigation for this vector.
  • Sanitization: There is no evidence of sanitization, filtering, or escaping for the repository content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — analyze