tech-entrepreneur-coach-adhd
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill configuration allows the use of web-browsing and search tools, which introduces a surface for indirect prompt injection. Malicious instructions placed on external websites could be ingested by the agent and influence its future actions.
- Ingestion points: External content is ingested via
mcp__firecrawl__firecrawl_search,mcp__brave-search__brave_web_search, andWebFetchas specified inSKILL.md. - Boundary markers: The instructions do not define delimiters or explicit warnings to ignore embedded instructions within retrieved web content.
- Capability inventory: The agent has file system modification capabilities (
Write,Edit,TodoWrite) which could be targeted by an injection. - Sanitization: There are no provided mechanisms for sanitizing or filtering external content before it is processed by the agent.
Audit Metadata