dbs-chatroom-austrian
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates untrusted user input into the prompt templates used to invoke sub-agent roles, creating a surface for potential instruction override.
- Ingestion points: User input is interpolated into the
{用户问题}and{新问题}variables withinSKILL.md. - Boundary markers: The sub-agent prompt templates (Hayek and Mises) lack delimiters or explicit instructions to ignore potentially malicious content embedded within the user's query.
- Capability inventory: The skill invokes the
Agent toolto generate responses from external Claude Sonnet instances based on the interpolated prompts. - Sanitization: No filtering, escaping, or validation logic is applied to the user input before it is passed to the models.
Audit Metadata