santa-method

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a workflow vulnerable to indirect prompt injection because it processes untrusted generator output within the context of reviewer agents.
  • Ingestion points: Untrusted data enters the agent context via the {output} variable interpolated into the REVIEWER_PROMPT in SKILL.md.
  • Boundary markers: The skill uses markdown headers (e.g., ## Output Under Review) as delimiters, but lacks explicit instructions for the reviewer agents to ignore instructions or commands embedded within the content being evaluated.
  • Capability inventory: The skill utilizes the Agent tool to spawn subagents for review and describes a fix_agent.execute capability to modify files based on review findings.
  • Sanitization: There is no evidence of sanitization, escaping, or schema validation performed on the generated output before it is passed to the reviewer agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — santa-method