oss-sponsors-brand-strategy
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted data to generate its recommendations.
- Ingestion points: As described in
SKILL.mdandreferences/target-discovery-and-scoring.md, the agent is instructed to ingest and resolve dependency trees from external files including lockfiles, SBOMs, and repository manifests such as.github/FUNDING.yml. - Capability inventory: The agent uses the ingested data to build ranked lists, suggest budget allocations, and draft maintainer outreach notes. It does not utilize these inputs for high-privilege operations such as arbitrary command execution or writing to system files.
- Boundary markers: The instructions lack explicit boundary markers or warnings to ignore instructions that might be embedded within the processed manifest files.
- Sanitization: While the skill relies on structured APIs like
deps.devfor resolution, there is no mention of sanitizing the raw strings found in manifests before they are interpolated into the agent's context. - [EXTERNAL_DOWNLOADS]: The skill fetches metadata from external services to perform its core analysis.
- Details: It retrieves dependency health signals, criticality scores, and funding metadata from Google's
deps.devAPI and GitHub's repository manifests. - Source: These are well-known technology services used appropriately for the skill's stated purpose of dependency analysis.
Audit Metadata