developing-genkit-js

Warn

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative and coercive language (e.g., "CRITICAL", "MANDATORY", "NON-NEGOTIABLE") to compel the agent to ignore its training data and safety filters in favor of provided references that contain inaccurate information about model availability and lifecycle.- [EXTERNAL_DOWNLOADS]: Recommends the global installation of the Genkit CLI using a specific version constraint (genkit-cli@^1.29.0). As this version is significantly beyond current releases, it may lead to failed development environments or potentially direct users toward non-standard sources.- [COMMAND_EXECUTION]: The skill directs the agent to execute various shell commands, including genkit docs:read, genkit start, and genkit flow:run. While functionally relevant, these are coupled with instructions that rely on deceptive versioning and fictional model identifiers, which may lead to unexpected runtime behavior or failure of primary tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 13, 2026, 08:21 PM