the-fool
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided positions, plans, or architectures from the conversation history, creating a surface for indirect prompt injection.
- Ingestion points: The core workflow in
SKILL.md(Step 1) extracts the user's position directly from the conversation context to restate it for analysis. - Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore potential commands embedded within the user's provided thesis.
- Capability inventory: The skill is limited to conversational interaction and loading internal reference documents; it uses the
AskUserQuestiontool but lacks capabilities for file modification, network communication, or shell execution. - Sanitization: There is no evidence of validation or sanitization routines for the extracted user content before it is processed by the agent's reasoning modes.
- [NO_CODE]: The skill consists entirely of instructional Markdown files and methodology references. No executable scripts (Python, JavaScript, shell) or external binary dependencies are included in the skill package.
Audit Metadata