1-start

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent state mechanism where user interview responses are saved to a learner-profile.md file intended for use by downstream skills (e.g., 2-scope, 3-prd). This ingestion of untrusted data into the agent's long-term context creates a vulnerability surface for indirect prompt injection. * Ingestion points: User interview answers collected via SKILL.md. * Boundary markers: The templates/learner-profile-template.md uses Markdown headers to delimit sections of the profile. * Capability inventory: The skill has file system write permissions for the devpost/ directory. * Sanitization: There is no explicit sanitization of user-provided strings before they are recorded in the profile.
  • [SAFE]: The skill demonstrates high security awareness by implementing a folder check to prevent execution in sensitive directories, ensuring personal context is excluded from git commits, and providing a direct negative constraint against requesting API keys or other credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:18 PM
Security Audit — agent-trust-hub — 1-start