scorched-earth
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses directive language designed to steer the agent away from its default behaviors (such as brevity and summarization). \n
- Evidence: Phrases like "These rules override every default behavior" and "What you MUST NOT do" are used to enforce thoroughness in SKILL.md.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and analyzes external, potentially untrusted content from codebases and URLs.\n
- Ingestion points: The target argument allows the user to specify directories, files, or URLs for analysis in SKILL.md.\n
- Boundary markers: Absent. The instructions do not define clear delimiters or "ignore" instructions for the content being analyzed.\n
- Capability inventory: The agent can read files, fetch content from URLs, and write detailed reports to the local disk (as specified in the Build and Intake modes in SKILL.md).\n
- Sanitization: Absent. There is no explicit sanitization or validation of the ingested content mentioned in the instructions.
Audit Metadata