moon-reflection-map
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions solely as a set of conversational instructions and does not include any scripts, executable code, or external tool dependencies.
- [PROMPT_INJECTION]: The skill is designed to process user-supplied reflective text, creating a surface for indirect prompt injection. However, it explicitly includes instructions to the agent to treat user input as untrusted data rather than commands. Evidence Chain for Indirect Prompt Injection surface: 1. Ingestion points: User reflective entries processed in SKILL.md Phases 1 through 5. 2. Boundary markers: The skill lacks formal delimiters but uses a step-by-step interactive structure. 3. Capability inventory: None; the skill lacks access to tools, the file system, or network operations. 4. Sanitization: Relies on behavioral instructions to the model to ignore embedded commands.
Audit Metadata