brainstorm
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) due to its data ingestion model. 1. Ingestion points: User input via the $ARGUMENTS variable, external data retrieved through the WebSearch tool, and project files accessed using the Read tool. 2. Boundary markers: The skill does not employ delimiters or specific instructions to isolate external content from the core logic of the agent. 3. Capability inventory: The agent has access to Write, Read, and WebSearch tools, which provides a broad capability surface that could be exploited if malicious instructions are ingested. 4. Sanitization: No evidence of validation, escaping, or filtering of ingested data was found in the provided instructions.
Audit Metadata