santa-method
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture involves taking potentially untrusted data (task specifications and generated outputs) and passing it to independent reviewer agents.
- Ingestion points:
SKILL.md(within theREVIEWER_PROMPTinterpolation of{task_spec}and{output}). - Boundary markers: The prompt uses structured Markdown headers (
## Task Specification,## Output Under Review) to separate data from instructions. - Capability inventory: The skill utilizes the
Agenttool to spawn independent sub-agents for evaluation tasks. - Sanitization: The skill does not implement explicit sanitization or filtering of the input strings before interpolation, relying on the dual-review logic to catch anomalies.
- [SAFE]: The skill demonstrates best practices for quality control, such as context isolation for reviewers and a convergence loop for fixing issues. No command execution, credential harvesting, or exfiltration patterns were found.
Audit Metadata