message-system-architect

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external content, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Competitor pages, persona documents, and truth-set exports are processed as external inputs as defined in the Instructions section.\n
  • Boundary markers: The skill includes specific instructions to treat all pasted source material as untrusted input and to ignore any instructions embedded within them, referencing a SECURITY.md file.\n
  • Capability inventory: The skill manages local file writes to the memory/ directory and utilizes a local script, registry-events.py, to propose registry entries.\n
  • Sanitization: Mitigation relies on explicit instructions to the agent to disregard embedded content; no programmatic sanitization is mentioned.\n- [COMMAND_EXECUTION]: The skill automates the submission of data to a local script, registry-events.py, using authorized operation parameters based on generated narrative content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:28 PM
Security Audit — agent-trust-hub — message-system-architect