santa-method
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a workflow vulnerable to indirect prompt injection because it processes untrusted generator output within the context of reviewer agents.
- Ingestion points: Untrusted data enters the agent context via the
{output}variable interpolated into theREVIEWER_PROMPTinSKILL.md. - Boundary markers: The skill uses markdown headers (e.g.,
## Output Under Review) as delimiters, but lacks explicit instructions for the reviewer agents to ignore instructions or commands embedded within the content being evaluated. - Capability inventory: The skill utilizes the
Agenttool to spawn subagents for review and describes afix_agent.executecapability to modify files based on review findings. - Sanitization: There is no evidence of sanitization, escaping, or schema validation performed on the generated output before it is passed to the reviewer agents.
Audit Metadata