analyze
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses the
{{ARGUMENTS}}template tag to interpolate user-provided tasks directly into the instruction set. An attacker could provide input designed to override the skill's core instructions, such as the 'Read-Only' constraint. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external, potentially untrusted repository data including code, configuration, and documentation.
- Ingestion points: Files, tests, configs, and docs from the target repository being analyzed in
SKILL.md. - Boundary markers: The skill lacks explicit delimiters or instructions to ignore malicious commands embedded within the analyzed file content, relying instead on the agent's general persona and the specific 'Read-Only' instructions.
- Capability inventory: The skill instructs the agent to read file paths and contracts. It specifically forbids editing files or running implementations, which serves as a significant mitigation for this vector.
- Sanitization: There is no evidence of sanitization, filtering, or escaping for the repository content before it is processed by the agent.
Audit Metadata