yds-software-evaluation
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of ingesting and processing untrusted source code.
- Ingestion points: The agent is instructed to read various project files including
package.json, entry points, business logic, and configuration files as specified in Phase 1.2. - Boundary markers: The instructions do not define clear delimiters or use "ignore embedded instructions" warnings when processing the target codebase, which could allow malicious instructions inside the code to influence agent behavior.
- Capability inventory: The agent has the capability to write both Markdown and JSON files to the
docs/evaluation/directory. - Sanitization: There are no instructions for sanitizing or escaping content read from files before incorporating it into the final report or JSON summary.
Audit Metadata