asb-positioning

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by ingesting untrusted marketing content and performing file-write operations based on that data.
  • Ingestion points: In Phase A, the skill collects copy to convert from either pasted text or local input files.
  • Boundary markers: The instructions do not explicitly require the use of delimiters or 'ignore embedded instructions' warnings to isolate user-provided content during the refinement process.
  • Capability inventory: The skill is authorized to create and append to a local file named POSITIONING.md and reads other project-related files such as VOTERS.md and needs-stack definitions.
  • Sanitization: No specific input sanitization or filtering is mentioned to prevent malicious instructions hidden in the marketing copy from influencing the agent's subsequent actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:33 PM
Security Audit — agent-trust-hub — asb-positioning