natural-center-extraction
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text data (essays, transcripts, scripts) to perform scoring and extraction. This creates a surface where instructions embedded in the source material could potentially influence the agent's behavior during the analysis phase.
- Ingestion points: The
source artifactinput defined in the frontmatter ofSKILL.mdis the primary entry point for untrusted data. - Boundary markers: The instructions lack explicit delimiters or guidance for the agent to ignore instructions embedded within the processed artifacts.
- Capability inventory: The skill declares
reads-filesystemandcreates-filesside effects inSKILL.md, which could be targeted by an injection attack. - Sanitization: No sanitization or validation of the input artifact content is mentioned in the workflow.
Audit Metadata