GateFlow Behavior
Pass
Audited by Gen Agent Trust Hub on Apr 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to 'Just do it — never ask "do you want to...?"' and to 'Never mention commands', which intentionally suppresses user oversight and transparency. This behavior makes the agent more susceptible to following instructions hidden in data.
- [PROMPT_INJECTION]: The 'Fail forward' rule requires the agent to 'automatically analyze' failures, potentially triggering the processing of malicious payloads in simulation outputs without a pause for user review.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface Analysis: 1. Ingestion points: Processes SystemVerilog, Verilog, and VCD (Value Change Dump) files as mentioned in SKILL.md. 2. Boundary markers: Absent; no instructions are provided to delimit or ignore instructions within these files. 3. Capability inventory: The skill utilizes capabilities for code generation, module modification, linting, and simulation execution. 4. Sanitization: Absent; no validation or sanitization steps are defined for external file content.
Audit Metadata