writeup-ctf
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data which creates a surface for indirect prompt injection attacks. 1. Ingestion points: The skill instructions involve analyzing 'local challenge artifacts', 'solved notes', and 'command logs' (SKILL.md). 2. Boundary markers: The skill does not define explicit delimiters to separate ingested data from agent instructions. 3. Capability inventory: No executable scripts, network tools, or shell commands are included in the skill, significantly mitigating the potential impact of an injection. 4. Sanitization: The skill promotes security best practices by including a dedicated reference for redacting secrets (API keys, tokens, session IDs) before final packaging (references/artifacts-redaction-and-packaging.md).
Audit Metadata