hypothesis-driven

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for investigating external artifacts like logs, binaries, and network captures, creating an attack surface for indirect prompt injection if those artifacts contain malicious instructions designed to influence the agent's logic.
  • Ingestion points: The skill ingests untrusted data from reproducers, artifacts, and logs (SKILL.md) as well as PCAPs and binaries (references/hypothesis-patterns.md).
  • Boundary markers: The hypothesis log format and recording instructions in SKILL.md lack explicit boundary markers or 'ignore instructions' warnings for data captured from these external sources.
  • Capability inventory: The workflow in SKILL.md and references/hypothesis-patterns.md suggests the use of diagnostic tools, debuggers (e.g., Frida), syscall tracers, and harnesses which could be manipulated if the agent follows instructions embedded in the analyzed data.
  • Sanitization: No sanitization or escaping of external content is specified in the skill files before it is recorded in the hypothesis log or interpreted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:21 PM
Security Audit — agent-trust-hub — hypothesis-driven