thread-homebase
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources (Codex task registry, task summaries, and recent turns) to generate reports. This creates an attack surface where malicious content within those tasks could attempt to influence the agent's output.
- Ingestion points: Codex task registry titles, summaries, and recent task turns in SKILL.md.
- Boundary markers: None present to delimit untrusted task data from instructions.
- Capability inventory: The skill can create or archive tasks within the Codex system when requested by the user.
- Sanitization: No explicit sanitization or validation of the ingested task data is described in the instructions.
Audit Metadata