feasibility-study
Pass
Audited by Gen Agent Trust Hub on Mar 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection. Ingestion points: The skill reads data from local source code files in the
src/directory through thegrepandreadtools as part of the research phase inreferences/analysis-phases.md. Boundary markers: There are no protective delimiters or instructions to the agent to ignore any command-like text or instructions found within the analyzed files. Capability inventory: The skill allows the use ofBashcommands, fileWriteoperations, and calls to themcp__codex__codex-replytool, which could be exploited if the agent follows instructions found in the researched code. Sanitization: No validation or sanitization is performed on the content of the researched files before it is processed or passed to the Codex discussion phase.
Audit Metadata