deslop
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a mechanism for indirect prompt injection by processing external text and having file-write access. * Ingestion points: User-pasted prose and text read from specified file paths (SKILL.md). * Boundary markers: No explicit tags or delimiters are defined to separate untrusted content from the skill's instructions. * Capability inventory: The skill includes instructions to write results back to the filesystem (SKILL.md). * Sanitization: There is no technical sanitization or filtering of input; the skill relies on instructional directives to avoid altering non-prose content.
Audit Metadata