internal-investigation

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection during document processing in 'Mode 2: Add data'.
  • Ingestion points: Untrusted document batches and interview notes ingested in 'Mode 2' (SKILL.md).
  • Boundary markers: Absent; instructions do not define specific delimiters to segregate processed data from the agent's core instructions.
  • Capability inventory: File system writing (log.yaml, memo.md), data summarization, and query responses based on ingested content.
  • Sanitization: Absent; ingested content is summarized and interpolated directly into structured logs and memos without validation.
  • [NO_CODE]: The skill is composed entirely of Markdown instructions and YAML data templates, containing no executable scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — internal-investigation