skills/aeondave/malskill/1337-brain/Gen Agent Trust Hub

1337-brain

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external content into a knowledge vault, creating a surface for indirect prompt injection where malicious instructions in source files could influence the agent's behavior during ingestion or retrieval tasks.
  • Ingestion points: Untrusted data enters the agent context through the ingest <path> command and via external source URL/path references described in SKILL.md under the 'Ingestion and retrieval' section.
  • Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the agent when processing ingested source content.
  • Capability inventory: The skill possesses filesystem write capabilities, including the ability to create directories, update summaries, and specifically 'add agent instruction files' under the project <name> command, which could be exploited to persist malicious instructions within the vault environment.
  • Sanitization: There is no mention of sanitization, filtering, or validation of the content being ingested from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:20 PM
Security Audit — agent-trust-hub — 1337-brain