windows-kernel-security

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Retrieves technical documentation, repository indices, and source code archives from the author's GitHub repository (gmh5225/awesome-game-security). These resources are used to provide detailed implementation context.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its data ingestion pattern: (1) Ingestion points: Fetches remote READMEs, repository descriptions, and code snapshots from raw.githubusercontent.com in SKILL.md. (2) Boundary markers: Missing explicit delimiters or instructions for the agent to treat the fetched content as untrusted data rather than instructions. (3) Capability inventory: The skill discusses high-privilege kernel operations; if the agent environment provides execution capabilities, the ingested content could attempt to influence them. (4) Sanitization: No sanitization or validation of the fetched content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 11:03 PM