1337-brain
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external content into a knowledge vault, creating a surface for indirect prompt injection where malicious instructions in source files could influence the agent's behavior during ingestion or retrieval tasks.
- Ingestion points: Untrusted data enters the agent context through the
ingest <path>command and via externalsource URL/pathreferences described inSKILL.mdunder the 'Ingestion and retrieval' section. - Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the agent when processing ingested source content.
- Capability inventory: The skill possesses filesystem write capabilities, including the ability to create directories, update summaries, and specifically 'add agent instruction files' under the
project <name>command, which could be exploited to persist malicious instructions within the vault environment. - Sanitization: There is no mention of sanitization, filtering, or validation of the content being ingested from external sources.
Audit Metadata