Fabric
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill provides an extensive framework of 240+ patterns that ingest arbitrary untrusted data (e.g., transcripts, meeting notes, articles). These patterns typically lack robust boundary markers or sanitization logic, making them susceptible to indirect prompt injection. Given the skill's capabilities to modify files and generate shell commands, this creates an attack surface where malicious data could influence high-privilege actions.
- [COMMAND_EXECUTION]: Patterns like 'create_command' are designed to generate functional terminal commands for security testing and development. While intended for user-guided execution, these are generated dynamically based on input instructions.
- [EXTERNAL_DOWNLOADS]: Automated update workflows in 'Workflows/UpdatePatterns.md' synchronize the pattern library from the project's official GitHub repository using git and CLI tools.
Audit Metadata