introduction-logic-builder
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill package includes a file named
eval_report_introduction-logic-builder_result.jsonwhich contains a pre-written security audit. This report explicitly claims a 'PASS' status for security and awards 'Full marks' for safety. This is a self-referential injection pattern designed to influence security evaluators or automated analysis tools by providing an authoritative-looking safety verdict within the skill's own data. - Ingestion points: The file
eval_report_introduction-logic-builder_result.jsonis included as part of the skill's reference context. - Boundary markers: There are no boundary markers or instructions to ignore these self-claims.
- Capability inventory: The skill is restricted to text generation and logical structuring; no file-system write, network exfiltration, or command execution capabilities were detected in the primary logic.
- Sanitization: No sanitization is performed on the included JSON evaluation report content.
- [METADATA_POISONING]: The inclusion of a static JSON evaluation report claiming 'PASS' status on security checks (e.g., 'security: PASS') acts as deceptive metadata. This could lead a user or an automated system to trust the skill based on its own internal claims rather than an independent audit.
Audit Metadata