idea-genie
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests repository context and user-provided questions which represent a potential attack surface for indirect prompt injection. The risk is mitigated by explicit instructions to isolate contexts and validate all outputs against a strict schema. * Ingestion points: Processes data from repo-context, task-question, and idea-portfolio.v1. * Boundary markers: Instructions mandate hydrating only necessary sources and maintaining sealed generation until all perspectives are complete. * Capability inventory: Executes local validation scripts (validate-output.sh, validate-challenge.sh) and writes JSON artifacts to a local scratch directory. * Sanitization: Strictly enforces JSON schema validation using jq.
- [SAFE]: No malicious patterns, unauthorized network activity, obfuscation, or credential exposure were detected. The skill uses standard local repository data to perform its intended analytical functions.
Audit Metadata