just-auto
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses imperative language to override standard assistant behavior and safety constraints. It explicitly demands 'full autonomy' and 'minimal process,' instructing the agent to proceed 'without approval gates.' The prompt also requires the agent to 'emit both blocks below verbatim' and 'Do not summarize, shorten, reword, or re-punctuate them,' which is a common pattern for maintaining the integrity of an instruction-override payload.
- [INDIRECT_PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection through its goal-based processing loop.
- Ingestion points: The agent ingests a 'task' from user input or conversation history to generate a 'Manifest' file.
- Boundary markers: There are no explicit instructions to ignore or sanitize malicious instructions that might be embedded in the task or generated manifest; conversely, the instructions state 'The Manifest is the contract' and must be followed until completion.
- Capability inventory: The skill has the capability to chain other tools, specifically
just-do, which implies file modification or command execution capabilities in an autonomous state. - Sanitization: There is no evidence of sanitization or validation of the task input before it is transformed into the 'Manifest' contract.
Audit Metadata