skills/a-canary/arc-skills/feedback/Gen Agent Trust Hub

feedback

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts a raw <description> string and interpolates it into a JSONL structure or API payload without sanitization.
  • Ingestion points: User input provided via the <description> argument in SKILL.md.
  • Boundary markers: None specified to isolate user-provided descriptions from the structural metadata.
  • Capability inventory: The skill performs file writes (to .arc/feedback.jsonl) and network operations (via the feedback-sink API binding).
  • Sanitization: No evidence of input validation, filtering, or escaping is present in the instructions or reference material.
  • [DATA_EXFILTRATION]: The feedback-sink binding in reference.md allows the skill to be configured to send data to an external URL via HTTP POST.
  • While intended for telemetry, this provides a potential exfiltration vector if the agent is manipulated into writing sensitive data into the feedback description.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:02 AM
Security Audit — agent-trust-hub — feedback