project-standards
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWSAFE
Full Analysis
- Indirect Prompt Injection (LOW): The skill instructs the agent to ingest data from untrusted external sources (project dependency files).
- Ingestion points: The instructions require reading
package.json,composer.json,go.mod,requirements.txt, andpyproject.toml(found inSKILL.md). - Boundary markers: No delimiters or instructions to ignore embedded commands within those files are provided.
- Capability inventory: The skill's capabilities are limited to influencing the agent's reasoning and code generation patterns (internal influence).
- Sanitization: No sanitization or validation of the content within these dependency files is suggested.
Audit Metadata