just-figure-out

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to investigate arbitrary topics by reading project files and external state, and it includes instructions to test hypotheses by running code in throwaway locations. This creates a potential path for malicious instructions embedded in the data being investigated to influence the agent's actions.
  • Ingestion points: The agent ingests a user-provided topic and related project artifacts (SKILL.md).
  • Boundary markers: The instructions lack explicit boundary markers or delimiters to separate untrusted data from the agent's internal instructions.
  • Capability inventory: The skill encourages running code in throwaway locations to verify hypotheses (SKILL.md).
  • Sanitization: There are no mentioned mechanisms for sanitizing or escaping the data discovered during investigations before it is used to formulate a "read" or test code.
  • [SAFE]: The skill maintains persistent state across sessions by writing logs to ~/.manifest-dev/logs/. This hidden directory in the user's home folder is used for append-only tracking of evidence and investigation progress.
  • [SAFE]: The skill explicitly defines its scope as investigation, stating that "agreement is fuel for exploring, not a green light" and that only the user naming a concrete change authorizes making modifications to the project.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 08:34 PM
Security Audit — agent-trust-hub — just-figure-out