Chief of Staff
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions define an operational framework where the agent ingests untrusted data from principals and decision logs to perform 'Cascading Updates' across a 'Document Dependency Map.' This ingestion-and-write pattern creates a surface for indirect prompt injection.
- Ingestion points: Principal requests, decision logs, and external documents being synchronized.
- Boundary markers: Absent; the skill lacks instructions to delimit external data or ignore instructions embedded within the processed documents.
- Capability inventory: Reading and writing to multiple files to maintain consistency across the dependency map.
- Sanitization: Absent; the skill does not specify validation, filtering, or escaping of the content it processes and propagates.
Audit Metadata