feedback
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts a raw
<description>string and interpolates it into a JSONL structure or API payload without sanitization. - Ingestion points: User input provided via the
<description>argument inSKILL.md. - Boundary markers: None specified to isolate user-provided descriptions from the structural metadata.
- Capability inventory: The skill performs file writes (to
.arc/feedback.jsonl) and network operations (via thefeedback-sinkAPI binding). - Sanitization: No evidence of input validation, filtering, or escaping is present in the instructions or reference material.
- [DATA_EXFILTRATION]: The
feedback-sinkbinding inreference.mdallows the skill to be configured to send data to an external URL via HTTP POST. - While intended for telemetry, this provides a potential exfiltration vector if the agent is manipulated into writing sensitive data into the feedback description.
Audit Metadata