taxonomy-modeling-design
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input files (
substrate-context.mdandphase-1-landscape-report.md) that may contain malicious instructions intended to influence the agent's behavior.\n - Ingestion points: Data is read via the
Readtool as specified in the Preconditions and work streams ofSKILL.md.\n - Boundary markers: Absent. The agent is not instructed to use specific delimiters or ignore embedded instructions within the input files.\n
- Capability inventory: The skill permits the use of
Bash,Write, andEdittools, creating a risk if an injection influences the agent's commands.\n - Sanitization: Absent. There are no instructions to sanitize or validate the content of the ingested reports before processing.
Audit Metadata