dbs-standard-answer
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user input (identified as 'original input' in SKILL.md) to extract core mechanisms and research questions, creating a surface where malicious instructions could be embedded in the analyzed data.
- Ingestion points: User input is extracted from 'original input', 'current conversation', and 'user-specified materials' in Step 1 of SKILL.md.
- Boundary markers: The skill instructs the agent to use specific markdown templates and perform a mandatory 'Proposition Review' (Step 2) to check for risks like absolute language, causal jumps, and definition swapping before proceeding.
- Capability inventory: The skill grants the agent the ability to perform network searches to verify theories and historical facts. It does not perform local code execution or filesystem writes.
- Sanitization: The skill implements a logical validation matrix in the 'Proposition Review' step and a 'Theory Verification' scoring system to filter out unreliable or unverified claims.
Audit Metadata