Chief of Staff

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions define an operational framework where the agent ingests untrusted data from principals and decision logs to perform 'Cascading Updates' across a 'Document Dependency Map.' This ingestion-and-write pattern creates a surface for indirect prompt injection.
  • Ingestion points: Principal requests, decision logs, and external documents being synchronized.
  • Boundary markers: Absent; the skill lacks instructions to delimit external data or ignore instructions embedded within the processed documents.
  • Capability inventory: Reading and writing to multiple files to maintain consistency across the dependency map.
  • Sanitization: Absent; the skill does not specify validation, filtering, or escaping of the content it processes and propagates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:24 AM
Security Audit — agent-trust-hub — Chief of Staff