sdo
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text and conversation history to generate diagrams. This represents a potential surface for indirect prompt injection if the processed data contains instructions designed to manipulate the agent's output. However, because the skill does not have access to any dangerous tools or system commands, the risk is negligible.
- Ingestion points: Processes
$ARGUMENTSand the previous conversation turn inSKILL.md. - Boundary markers: Absent.
- Capability inventory: None (The skill has no associated scripts and no tool permissions).
- Sanitization: Absent.
- [NO_CODE]: The skill consists entirely of instructions and configuration. It does not include any executable scripts, binaries, or package dependencies.
Audit Metadata