physics-rendering-expert

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions and configuration establish a vulnerability surface for indirect prompt injection attacks by integrating external data sources with powerful execution tools.\n
  • Ingestion points: The skill is configured to use mcp__firecrawl__firecrawl_search and WebFetch in SKILL.md to ingest content from external websites.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat fetched content as potentially untrusted data or to ignore embedded commands.\n
  • Capability inventory: The skill permits access to Bash, Write, and Edit tools as defined in SKILL.md, providing a path for malicious instructions in external data to execute actions on the host system.\n
  • Sanitization: The documentation and implementation references do not specify any validation or sanitization protocols for external data processed by the simulation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 12:40 PM
Security Audit — agent-trust-hub — physics-rendering-expert