expansive-inquiry
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the interpolation of untrusted user input into its internal cognitive orchestration.
- Ingestion points: The user-supplied {topic} variable is ingested in SKILL.md and passed as context to all six lens agents (Scope, Logic, Mythos, Bridge, Meta, and Pattern).
- Boundary markers: The prompt templates utilize double quotes (e.g., TOPIC: "{topic}") to delimit user input but do not include explicit instructions for the AI to ignore any embedded directives, system overrides, or role-play instructions contained within the topic.
- Capability inventory: The skill invokes the Agent tool to spawn multiple sub-agents and utilizes file-writing capabilities to generate a series of Markdown documents and an HTML report file.
- Sanitization: There are no defined procedures for sanitizing or validating the topic content to prevent malicious instructions from potentially influencing the behavior of the downstream sub-agents.
Audit Metadata