asb-positioning
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by ingesting untrusted marketing content and performing file-write operations based on that data.
- Ingestion points: In Phase A, the skill collects copy to convert from either pasted text or local input files.
- Boundary markers: The instructions do not explicitly require the use of delimiters or 'ignore embedded instructions' warnings to isolate user-provided content during the refinement process.
- Capability inventory: The skill is authorized to create and append to a local file named
POSITIONING.mdand reads other project-related files such asVOTERS.mdand needs-stack definitions. - Sanitization: No specific input sanitization or filtering is mentioned to prevent malicious instructions hidden in the marketing copy from influencing the agent's subsequent actions.
Audit Metadata