expansive-inquiry

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the interpolation of untrusted user input into its internal cognitive orchestration.
  • Ingestion points: The user-supplied {topic} variable is ingested in SKILL.md and passed as context to all six lens agents (Scope, Logic, Mythos, Bridge, Meta, and Pattern).
  • Boundary markers: The prompt templates utilize double quotes (e.g., TOPIC: "{topic}") to delimit user input but do not include explicit instructions for the AI to ignore any embedded directives, system overrides, or role-play instructions contained within the topic.
  • Capability inventory: The skill invokes the Agent tool to spawn multiple sub-agents and utilizes file-writing capabilities to generate a series of Markdown documents and an HTML report file.
  • Sanitization: There are no defined procedures for sanitizing or validating the topic content to prevent malicious instructions from potentially influencing the behavior of the downstream sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — expansive-inquiry