agile-skill-feedback

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to its core function of processing external data.
  • Ingestion points: The agent is instructed to read '$ARGUMENTS' from a slash command and inspect external 'evidence artifacts' or 'diffs' in its local environment.
  • Boundary markers: The instructions do not specify any delimiters (such as XML tags or triple quotes) or 'ignore' instructions to isolate the content of untrusted artifacts from the agent's logic.
  • Capability inventory: The skill has permission to read local files (including other skill files) and is expected to generate and write new feedback artifacts based on its analysis.
  • Sanitization: There is no requirement or logic provided for sanitizing or validating the contents of the evidence before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 01:19 PM
Security Audit — agent-trust-hub — agile-skill-feedback