systemic-ingestion-normalization

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from multiple potentially untrusted external files including substrate-context.md, phase-1-landscape-report.md, phase-2-taxonomy-model.md, and phase-3-environment-spec.md. Malicious instructions embedded within these reports could influence the agent's behavior during the migration process.
  • Ingestion points: The skill explicitly instructs the agent to read four distinct files in full (substrate-context.md, phase-1-landscape-report.md, phase-2-taxonomy-model.md, and phase-3-environment-spec.md) before beginning the work streams.
  • Boundary markers: The instructions do not define clear delimiters or provide 'ignore embedded instructions' directives for the data being read from the legacy substrate or the environment specifications.
  • Capability inventory: The skill is configured with high-privilege tools including Bash, Write, Edit, Read, Glob, and Grep, which could be exploited if an indirect injection successfully overrides agent behavior.
  • Sanitization: While the skill focuses on data normalization and schema alignment, it lacks sanitization or validation logic to identify and filter out natural language instructions embedded within the data fields of the legacy entities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — systemic-ingestion-normalization