skills/cranot/super-hermes/prism-scan/Gen Agent Trust Hub

prism-scan

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process arbitrary user-provided artifacts (code, documentation, specs) and local project files (.prism-history.md) to perform its analysis. The instructions lack explicit boundary markers or sanitization steps for this untrusted content, which could allow maliciously crafted input within the analyzed files to influence the agent's behavior during the analysis phase.
  • Ingestion points: The skill reads the user-provided artifact and the .prism-history.md file (SKILL.md, Step 0 and Step 2).
  • Boundary markers: Absent; there are no instructions to the agent to treat the contents of these files as untrusted data or to use specific delimiters.
  • Capability inventory: The skill is limited to the Read tool, which restricts its ability to perform high-impact actions like network exfiltration or shell execution, but it still produces complex textual output that could be manipulated.
  • Sanitization: Absent; there is no validation or filtering of the content retrieved from the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:15 PM
Security Audit — agent-trust-hub — prism-scan