alterlab-nmc-digital-ethics
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core workflow of processing untrusted external data.
- Ingestion points: The agent is instructed to 'Read existing project files' and 'search the web' for ethical frameworks, policies, and case studies (SKILL.md).
- Boundary markers: The instructions do not define clear delimiters or specific warnings to ignore instructions embedded within the processed project files or web content.
- Capability inventory: The skill possesses the ability to perform web searches, read local files, and write new markdown files to the project directory (SKILL.md).
- Sanitization: There is no mention of sanitizing or validating the content retrieved from external sources or files before it is used to generate new deliverables.
Audit Metadata