dimension-surfacing

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external text prompts (referred to as grains), creating a surface for potential instruction injection.
  • Ingestion points: The skill reads input from grain-context.md or direct arguments as described in Step 1 of the Procedure section.
  • Boundary markers: While the skill instructs the agent to read the grain literally and verbatim, there are no explicit delimiters or instructions to disregard potential commands embedded within the text.
  • Capability inventory: The skill utilizes Read, Write, Edit, and Agent tools to generate the phase-1-dimensions.md artifact.
  • Sanitization: The skill does not implement specific sanitization, filtering, or validation logic for the content extracted from the grain before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — dimension-surfacing