filament-ai-agents

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to ingest and follow instructions from third-party Markdown documentation located in the vendor/filament/ directory.
  • Ingestion points: Documentation files (*.md) within the installed Filament packages.
  • Boundary markers: The instructions lack delimiters or warnings to ignore embedded directives within the third-party content.
  • Capability inventory: The agent is tasked with writing code and executing repository-defined verification checks based on the documentation read.
  • Sanitization: No sanitization or filtering of the external documentation content is specified.
  • [COMMAND_EXECUTION]: The skill uses local commands such as composer show, composer config, and rg (ripgrep) to discover and inspect project documentation.
  • [EXTERNAL_DOWNLOADS]: The skill provides procedures for running composer install to fetch dependencies from official registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:27 AM
Security Audit — agent-trust-hub — filament-ai-agents