fpf-problem-solving

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as an 'agentic RAG' system, guiding the agent to ingest and analyze user-supplied problem descriptions, architectural proposals, and project documentation using the First Principles Framework (FPF).
  • Ingestion points: The skill instructs the agent to assist with the user's 'project / problem / programme' (identified in SKILL.md), which is an entry point for untrusted data.
  • Boundary markers: The instructions lack explicit boundary markers or delimiters (e.g., 'ignore embedded instructions' warnings) to help the agent distinguish between data intended for analysis and potential instructions hidden within that data.
  • Capability inventory: As an AI coding agent skill, the agent may possess tools for file system access or command execution that could be targeted by an attacker through embedded instructions.
  • Sanitization: No sanitization or validation logic is defined for external content before it is interpolated into the reasoning context, increasing the risk of the agent obeying malicious instructions hidden in the user's project descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:56 AM
Security Audit — agent-trust-hub — fpf-problem-solving