systemic-ingestion-normalization
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from multiple potentially untrusted external files including
substrate-context.md,phase-1-landscape-report.md,phase-2-taxonomy-model.md, andphase-3-environment-spec.md. Malicious instructions embedded within these reports could influence the agent's behavior during the migration process. - Ingestion points: The skill explicitly instructs the agent to read four distinct files in full (
substrate-context.md,phase-1-landscape-report.md,phase-2-taxonomy-model.md, andphase-3-environment-spec.md) before beginning the work streams. - Boundary markers: The instructions do not define clear delimiters or provide 'ignore embedded instructions' directives for the data being read from the legacy substrate or the environment specifications.
- Capability inventory: The skill is configured with high-privilege tools including
Bash,Write,Edit,Read,Glob, andGrep, which could be exploited if an indirect injection successfully overrides agent behavior. - Sanitization: While the skill focuses on data normalization and schema alignment, it lacks sanitization or validation logic to identify and filter out natural language instructions embedded within the data fields of the legacy entities.
Audit Metadata