tldr
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to summarize external data provided by the user, such as files, links, and transcripts. This establishes a surface for indirect prompt injection, where an attacker could embed malicious instructions in the content being summarized to manipulate the agent's behavior.
- Ingestion points: As described in
SKILL.md, the skill ingests data from pasted blocks, files, links, threads, and transcripts. - Boundary markers: The instructions do not employ explicit delimiters (like XML tags) or specific boundary markers to separate the untrusted input from the processing instructions.
- Capability inventory: The YAML frontmatter includes
disable-model-invocation: true, which restricts the agent from calling any tools or performing actions based on injected instructions, neutralizing the primary impact of such attacks. - Sanitization: The skill relies on natural language instructions to remain 'faithful, not creative' and to 'add nothing, invent nothing,' but lacks programmatic sanitization or filtering of the processed content.
- [NO_CODE]: The skill contains only instructional text in markdown format and does not include any executable scripts, binaries, or automated configuration files.
Audit Metadata