skills/seabbs/skills/working-on/Gen Agent Trust Hub

working-on

Pass

Audited by Gen Agent Trust Hub on Mar 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by ingesting untrusted data from local project files.
  • Ingestion points: The skill reads file names and content from DESCRIPTION, Project.toml, and README.md files (specifically titles and first lines) across the directory hierarchy in SKILL.md.
  • Boundary markers: No explicit delimiters or boundary markers are defined to isolate the extracted content from the instructions in the generated CLAUDE.md file.
  • Capability inventory: The skill has the capability to read any file within the directory hierarchy and write/update a CLAUDE.md file in the current working directory.
  • Sanitization: There is no evidence of sanitization or filtering of the content extracted from README.md or other configuration files before it is placed into the inventory.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 8, 2026, 07:16 AM