reference-generator

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Prompt Injection (HIGH): Vulnerable to Indirect Prompt Injection (Category 8). * Ingestion points: The skill reads /docs/course-description.md and fetches external web content via WebFetch in Step 4. * Capability inventory: The agent has the power to Write new files, Edit existing chapter index files, and modify mkdocs.yml. * Boundary markers: No delimiters or isolation techniques are used when processing the untrusted content. * Sanitization: No input validation is performed on the data retrieved from external sources.
  • Command Execution (LOW): The skill executes the ls command to find chapter directories. This is a standard environment discovery task but falls under command execution.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 02:41 AM