elon-musk-perspective
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions define an 'Agentic Protocol' that requires the agent to use external tools like
WebSearchto retrieve real-world information, such as cost structures, manufacturing data, and technical parameters. This ingested data is then used to formulate a response, which creates a vulnerability where malicious content on the internet could potentially influence the agent's behavior. - Ingestion points: The
Step 2: 马斯克式研究(Musk-style research) section inSKILL.mdexplicitly requires the use ofWebSearchto fetch data regarding BOM (Bill of Materials), physical limits, and competitor dynamics. - Boundary markers: The skill contains internal role-play boundaries (STOP and EXIT triggers), but it lacks specific boundary markers or instructions to ignore potential injections within the external data fetched via search.
- Capability inventory: The skill does not possess high-risk capabilities such as file system writes, arbitrary command execution, or network exfiltration beyond the platform's standard tool usage.
- Sanitization: There are no instructions for sanitizing or filtering the content retrieved from external searches.
Audit Metadata