backend-development
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHPROMPT_INJECTIONNO_CODE
Full Analysis
- Indirect Prompt Injection (HIGH): The skill creates a significant attack surface by instructing the agent to analyze external project files and then perform high-privilege code generation. * Ingestion points: Analyzes user-provided source code and project directories as described in 'Implementation Principles'. * Boundary markers: Absent; there are no instructions to differentiate between developer intent and instructions embedded in the analyzed code. * Capability inventory: The skill specifies capabilities for implementing OAuth 2.1, JWT, and CI/CD pipelines. * Sanitization: Absent; no mechanism exists to sanitize or escape instructions within analyzed content.
- No Executable Code (INFO): No scripts or binaries were found within the provided skill file.
Recommendations
- AI detected serious security threats
Audit Metadata