first-principles-coach

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection via external data ingestion.\n
  • Ingestion points: Phase 1 of SKILL.md instructs the agent to use WebFetch to read content from a user-provided URL to establish business context.\n
  • Boundary markers: The skill instructions do not specify the use of delimiters or clear separation between system instructions and untrusted external data.\n
  • Capability inventory: The skill requests the ability to read external data. No high-risk capabilities such as arbitrary command execution, file writing, or network exfiltration were identified in the skill's own logic.\n
  • Sanitization: No logic is provided to sanitize or validate the content fetched from external URLs before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 06:47 AM
Security Audit — agent-trust-hub — first-principles-coach