dimension-surfacing
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external text prompts (referred to as grains), creating a surface for potential instruction injection.
- Ingestion points: The skill reads input from grain-context.md or direct arguments as described in Step 1 of the Procedure section.
- Boundary markers: While the skill instructs the agent to read the grain literally and verbatim, there are no explicit delimiters or instructions to disregard potential commands embedded within the text.
- Capability inventory: The skill utilizes Read, Write, Edit, and Agent tools to generate the phase-1-dimensions.md artifact.
- Sanitization: The skill does not implement specific sanitization, filtering, or validation logic for the content extracted from the grain before it is processed.
Audit Metadata