intake-project

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as manuscript drafts, abstracts, and project folders which may contain instructions designed to manipulate the agent's logic.\n
  • Ingestion points: SKILL.md specifies reading project folders, manuscripts, abstracts, and mixed folder contents.\n
  • Boundary markers: There are no explicit markers or instructions defined to isolate or disregard instructions that might be embedded within the processed research documents.\n
  • Capability inventory: The skill utilizes powerful tools including Bash, Write, and Edit as listed in SKILL.md frontmatter, which increases the potential impact of an injection.\n
  • Sanitization: The instructions do not specify any sanitization or filtering of the content read from external files before it is used to determine project state or recommended actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:59 AM
Security Audit — agent-trust-hub — intake-project