kiss
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze potentially untrusted external data, creating an attack surface for indirect prompt injection.\n- Ingestion points: Processes content from documentation, code layouts, issue graphs, pull requests, and user-provided pastes as defined in SKILL.md.\n- Capability inventory: While stated as read-only by default, the skill can suggest or invoke other functional skills like refactor-it, issues narrow, and agents design based on the data it analyzes.\n- Boundary markers: The instructions lack specific boundary markers or instructions to ignore embedded commands when interpolating analyzed data into the agent context.\n- Sanitization: There is no evidence of sanitization, filtering, or validation logic for the ingested external content.
Audit Metadata