llm-top-10

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted code files, creating a surface for indirect prompt injection. [1] Ingestion points: Source files provided in arguments are processed via the Read tool. [2] Boundary markers: A dedicated Safety Notice in Section 8 warns against following embedded instructions. [3] Capability inventory: The skill uses a restricted set of tools (Read, Grep, Glob) and has no execution or write permissions. [4] Sanitization: Instructions explicitly direct the agent to analyze rather than execute content.
  • [PROMPT_INJECTION]: Descriptive examples of common injection strings like 'ignore previous instructions' are included for auditing reference and do not constitute active attacks against the agent.
  • [EXTERNAL_DOWNLOADS]: External references are limited to official security documentation on the OWASP project website, which is a well-known and trusted source for security professionals.
  • [DATA_EXFILTRATION]: No data exfiltration patterns detected. The skill instructions focus on identifying potential leaks in the applications being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:07 AM
Security Audit — agent-trust-hub — llm-top-10