2-scope
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies and processes untrusted data from the user conversation and local project files, creating a surface for indirect prompt injection.\n
- Ingestion points: Reads project context from
devpost/learner-profile.mdand extracts content from the user's "brain dump" and interview responses.\n - Boundary markers: Instructions do not specify the use of delimiters or specific "ignore embedded instructions" warnings when handling this external content.\n
- Capability inventory: The skill has the capability to write files (
devpost/scope.mdanddevpost/scope.html).\n - Sanitization: There is no mention of sanitizing or escaping the user-provided text before it is written to files, which could lead to technical issues such as cross-site scripting (XSS) in the generated HTML companion or unintended instruction execution in downstream skills that read these files.
Audit Metadata