mlir-development

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The skill instructs the agent to fetch data from https://raw.githubusercontent.com/gmh5225/awesome-llvm-security/refs/heads/main/README.md. This source is not within the trusted organizations list defined in the [TRUST-SCOPE-RULE].
  • [PROMPT_INJECTION] (LOW): The external fetch creates a vulnerability for Indirect Prompt Injection (Category 8).
  • Ingestion points: The README file from the external repository is ingested into the agent's context (SKILL.md).
  • Boundary markers: No specific boundary markers or 'ignore' instructions are present for the fetched content.
  • Capability inventory: The skill context includes LLVM/MLIR tool usage and general agent reasoning capabilities.
  • Sanitization: No sanitization or verification process is defined for the external documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:23 PM