human-gate-designer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a design pattern for workflows that ingest and process human feedback, which introduces an attack surface for indirect prompt injection in the target implementation.
  • Ingestion points: The 'Feedback Injection' section in SKILL.md describes collecting 'text input for human feedback' via a UI gate.
  • Boundary markers: The recommended prompt template uses basic labels (Human feedback: "[...]") but does not explicitly instruct the agent to treat the content as data or provide strict delimiters to prevent command injection from the human reviewer.
  • Capability inventory: The skill itself uses standard Read, Write, and Edit tools; however, the gates it designs are intended to trigger re-execution of other nodes in a DAG.
  • Sanitization: The skill does not currently provide guidance on sanitizing or escaping the human-provided feedback before it is interpolated into the re-execution prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — human-gate-designer