alterlab-vcd-color-theorist
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified. The skill instructions mandate reading external project files and performing web searches to inform its output, creating a vector where malicious instructions embedded in those sources could influence agent behavior.
- Ingestion points: The skill actively reads existing project files, including brand guidelines and mood boards, and performs web searches for industry trends (SKILL.md).
- Boundary markers: The instructions do not specify any delimiters or warnings to ignore embedded instructions within the data it ingests.
- Capability inventory: The skill has capabilities to read and write markdown files within the project directory and perform web searches (SKILL.md).
- Sanitization: There is no mention of sanitization, validation, or filtering of the content retrieved from external sources before it is processed by the agent.
Audit Metadata