900-feedback-loop
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external artifacts (code, documents, etc.) for review, which creates a vulnerability to indirect prompt injection.
- Ingestion points: The workflow described in
SKILL.mdtakes a 'review brief' and 'apply-fix brief' which target specific artifacts or scopes for analysis. - Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or triple backticks) or 'ignore embedded instructions' warnings when passing the artifact content to the Review subagent.
- Capability inventory: The 'Apply-Fix' subagent is granted the authority to modify files on the filesystem ('Apply-Fix only edits files already in scope').
- Sanitization: There is no evidence of content sanitization or validation to prevent malicious instructions embedded in the reviewed artifacts from being interpreted as commands by the subagents.
Audit Metadata