skill-chain-prompts
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill functions as a meta-orchestrator that processes YAML workflow definitions to drive agent behavior and invoke subsequent skills. This architecture creates an inherent surface for indirect prompt injection, where malicious or malformed chain definitions could be used to influence the agent's decision-making process or execute unintended commands.
- Ingestion points: Workflow definitions are sourced from YAML files within the
assets/chains/directory or supplied dynamically by the user via the/skill-chain-prompts runand/skill-chain-prompts createcommands. - Boundary markers: The execution model described in
references/execution-model.mdfocuses on sequential processing and context passing but does not specify robust delimiters or instructions to prevent the agent from obeying malicious instructions embedded within step descriptions or context fields. - Capability inventory: The orchestration logic allows for the invocation of any system skill (e.g.,
/api-design-patterns,/backend-implementation-patterns) and the passing of arbitrary arguments and context strings to those skills. - Sanitization: The documentation provides validation rules for schema integrity (e.g., unique IDs, circular dependencies) in
references/chain-format.md, but there is no mention of sanitizing natural language inputs or filtering potentially harmful skill arguments.
Audit Metadata