app-brief
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from APP_DEFINITION.md to generate or update APP_BRIEF.md, which represents a surface for indirect prompt injection. * Ingestion points: APP_DEFINITION.md (read operation) * Boundary markers: Absent; the instructions do not implement delimiters to isolate instructions from data. * Capability inventory: File system read and write operations on specific markdown files. * Sanitization: Absent; input text is directly interpolated into the brief template.
- [EXTERNAL_DOWNLOADS]: The skill references documentation and community repositories at docs.cribl.io and github.com/Cribl-Community.
Audit Metadata