wait-what
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest content from an external file (CONTEXT.md). This creates a data ingestion surface where instructions could potentially be embedded in the data source.
- Ingestion points: References
CONTEXT.mdin the instruction body ofSKILL.md. - Boundary markers: None present.
- Capability inventory: The skill explicitly disables tool usage via
disable-model-invocation: truein the frontmatter, minimizing the risk of harmful actions. - Sanitization: None present.
Audit Metadata