red-team
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill generates engagement plans by interpolating user-supplied input into text and JSON artifacts. If these generated artifacts are subsequently processed by other automated AI agents or tools, malicious content in the input could influence their behavior.
- Ingestion points: User input enters the skill through command-line arguments (
--target,--duration,--compliance) processed byscripts/engagement_planner.py. - Boundary markers: The generated output (human-readable text or JSON) does not utilize specific delimiters or warnings to isolate user-provided strings from the rest of the document structure.
- Capability inventory: The
scripts/engagement_planner.pytool possesses file-writing capabilities (Path.write_text), allowing it to save generated plans to user-specified local paths. - Sanitization: The script performs basic regex validation on the duration string but does not sanitize or escape target strings or other user-provided metadata before including them in the final engagement plan.
Audit Metadata