tldr

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to summarize external data provided by the user, such as files, links, and transcripts. This establishes a surface for indirect prompt injection, where an attacker could embed malicious instructions in the content being summarized to manipulate the agent's behavior.
  • Ingestion points: As described in SKILL.md, the skill ingests data from pasted blocks, files, links, threads, and transcripts.
  • Boundary markers: The instructions do not employ explicit delimiters (like XML tags) or specific boundary markers to separate the untrusted input from the processing instructions.
  • Capability inventory: The YAML frontmatter includes disable-model-invocation: true, which restricts the agent from calling any tools or performing actions based on injected instructions, neutralizing the primary impact of such attacks.
  • Sanitization: The skill relies on natural language instructions to remain 'faithful, not creative' and to 'add nothing, invent nothing,' but lacks programmatic sanitization or filtering of the processed content.
  • [NO_CODE]: The skill contains only instructional text in markdown format and does not include any executable scripts, binaries, or automated configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 12:33 PM