artifact-integrator

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface detected within the artifact analysis workflow.
  • Ingestion points: The skill ingests untrusted data from the .claude/context/runtime/integration-queue.jsonl file and reads the contents of arbitrary files listed in the affectedFiles array during backward-propagation validation (Step 3.5).
  • Boundary markers: The protocol does not specify the use of delimiters or 'ignore embedded instructions' warnings when handling content from external sources.
  • Capability inventory: The skill has access to sensitive tools including Bash, Write, Edit, TaskCreate, and TaskUpdate.
  • Sanitization: No sanitization, escaping, or validation logic is applied to the extracted pattern or rationale strings before they are interpolated into task descriptions and integration reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 02:04 PM