governance-evolution-protocol
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process several external documents (e.g., phase-4-ingestion-report.md and substrate-context.md) to generate its final output. Maliciously crafted content within these reports could attempt to influence the agent's behavior.
- Ingestion points: The skill instructs the agent to read five specific markdown files from the working directory: substrate-context.md, phase-1-landscape-report.md, phase-2-taxonomy-model.md, phase-3-environment-spec.md, and phase-4-ingestion-report.md.
- Boundary markers: The instructions lack explicit markers or delimiters to help the agent distinguish between instructional guidelines and the data contained within the ingested reports.
- Capability inventory: The skill environment grants the agent access to Bash, Write, Edit, Read, Glob, and Grep tools, providing a capability surface that could be targeted if an injection occurs.
- Sanitization: There are no defined procedures for validating or sanitizing the content of the external reports before the agent processes them.
Audit Metadata