internal-investigation
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection during document processing in 'Mode 2: Add data'.
- Ingestion points: Untrusted document batches and interview notes ingested in 'Mode 2' (SKILL.md).
- Boundary markers: Absent; instructions do not define specific delimiters to segregate processed data from the agent's core instructions.
- Capability inventory: File system writing (log.yaml, memo.md), data summarization, and query responses based on ingested content.
- Sanitization: Absent; ingested content is summarized and interpolated directly into structured logs and memos without validation.
- [NO_CODE]: The skill is composed entirely of Markdown instructions and YAML data templates, containing no executable scripts or binaries.
Audit Metadata