2-scope

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies and processes untrusted data from the user conversation and local project files, creating a surface for indirect prompt injection.\n
  • Ingestion points: Reads project context from devpost/learner-profile.md and extracts content from the user's "brain dump" and interview responses.\n
  • Boundary markers: Instructions do not specify the use of delimiters or specific "ignore embedded instructions" warnings when handling this external content.\n
  • Capability inventory: The skill has the capability to write files (devpost/scope.md and devpost/scope.html).\n
  • Sanitization: There is no mention of sanitizing or escaping the user-provided text before it is written to files, which could lead to technical issues such as cross-site scripting (XSS) in the generated HTML companion or unintended instruction execution in downstream skills that read these files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:18 PM
Security Audit — agent-trust-hub — 2-scope