design
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes user input to automate the invocation of sub-skills, which is a potential surface for indirect prompt injection.
- Ingestion points: User messages and conversation context in SKILL.md.
- Boundary markers: None defined to isolate user input from system instructions.
- Capability inventory: Allowed access to Skill, Read, Bash, Edit, and Write tools.
- Sanitization: No input sanitization or validation logic is present.
Audit Metadata