natural-center-extraction

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text data (essays, transcripts, scripts) to perform scoring and extraction. This creates a surface where instructions embedded in the source material could potentially influence the agent's behavior during the analysis phase.
  • Ingestion points: The source artifact input defined in the frontmatter of SKILL.md is the primary entry point for untrusted data.
  • Boundary markers: The instructions lack explicit delimiters or guidance for the agent to ignore instructions embedded within the processed artifacts.
  • Capability inventory: The skill declares reads-filesystem and creates-files side effects in SKILL.md, which could be targeted by an injection attack.
  • Sanitization: No sanitization or validation of the input artifact content is mentioned in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — natural-center-extraction