parametrize-and-cite

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and transform untrusted third-party artifacts, including READMEs, configuration files, and reports. There is an inherent risk that these documents could contain embedded instructions intended to influence the agent's behavior during the transformation process. The skill lacks explicit boundary markers or delimiters for the processed content and relies on the agent to interpret the entire document structure. However, this risk is categorized as low because the skill's primary capabilities are limited to text manipulation and documentation generation (emitting transformed text, .env examples, and bibliographies) and do not include high-risk capabilities like network access or command execution.
  • Ingestion points: The skill processes any document or data provided as input via triggers such as request:parametrize or content:contains-hard-coded-values in SKILL.md.
  • Boundary markers: None identified in the transformation pipeline instructions.
  • Capability inventory: The skill performs text analysis, categorization, and replacement. It does not invoke subprocesses, perform network operations, or write to the file system beyond generating the requested output artifacts.
  • Sanitization: The skill explicitly identifies SECRET_* variables and instructs the agent to never include real secret values in the output, using placeholders instead.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — parametrize-and-cite