Research Topic

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWNO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE] (SAFE): The skill is composed strictly of markdown templates and process instructions for an AI agent. No shell commands, scripts, or system-level interactions are present.
  • [Indirect Prompt Injection] (LOW): 1. Ingestion points: External codebase files located in pkg/, docs/, and examples/ directories. 2. Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are used for ingested content. 3. Capability inventory: The skill has no capabilities for code execution, file modification, or network access. 4. Sanitization: No sanitization logic is defined for the content extracted from the codebase. Severity is LOW because it is restricted to reasoning and display only.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 09:54 AM