material-3

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an 'audit' command that accepts external URLs or file paths for design compliance checking, creating a vulnerability surface where malicious instructions within the audited data could attempt to influence agent behavior. 1. Ingestion points: The 'audit' argument hint in SKILL.md and the corresponding procedure. 2. Boundary markers: The instructions do not specify any boundary markers or delimiters to isolate untrusted content. 3. Capability inventory: The skill suggests using shell commands like grep and browser-based tools to inspect external source code and pages. 4. Sanitization: No specific instructions for sanitizing or escaping the data fetched from the ingestion points are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:55 PM
Security Audit — agent-trust-hub — material-3