filament-ai-agents
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to ingest and follow instructions from third-party Markdown documentation located in the
vendor/filament/directory. - Ingestion points: Documentation files (
*.md) within the installed Filament packages. - Boundary markers: The instructions lack delimiters or warnings to ignore embedded directives within the third-party content.
- Capability inventory: The agent is tasked with writing code and executing repository-defined verification checks based on the documentation read.
- Sanitization: No sanitization or filtering of the external documentation content is specified.
- [COMMAND_EXECUTION]: The skill uses local commands such as
composer show,composer config, andrg(ripgrep) to discover and inspect project documentation. - [EXTERNAL_DOWNLOADS]: The skill provides procedures for running
composer installto fetch dependencies from official registries.
Audit Metadata