physics-rendering-expert
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions and configuration establish a vulnerability surface for indirect prompt injection attacks by integrating external data sources with powerful execution tools.\n
- Ingestion points: The skill is configured to use
mcp__firecrawl__firecrawl_searchandWebFetchinSKILL.mdto ingest content from external websites.\n - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat fetched content as potentially untrusted data or to ignore embedded commands.\n
- Capability inventory: The skill permits access to
Bash,Write, andEdittools as defined inSKILL.md, providing a path for malicious instructions in external data to execute actions on the host system.\n - Sanitization: The documentation and implementation references do not specify any validation or sanitization protocols for external data processed by the simulation logic.
Audit Metadata