just-figure-out
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to investigate arbitrary topics by reading project files and external state, and it includes instructions to test hypotheses by running code in throwaway locations. This creates a potential path for malicious instructions embedded in the data being investigated to influence the agent's actions.
- Ingestion points: The agent ingests a user-provided topic and related project artifacts (SKILL.md).
- Boundary markers: The instructions lack explicit boundary markers or delimiters to separate untrusted data from the agent's internal instructions.
- Capability inventory: The skill encourages running code in throwaway locations to verify hypotheses (SKILL.md).
- Sanitization: There are no mentioned mechanisms for sanitizing or escaping the data discovered during investigations before it is used to formulate a "read" or test code.
- [SAFE]: The skill maintains persistent state across sessions by writing logs to
~/.manifest-dev/logs/. This hidden directory in the user's home folder is used for append-only tracking of evidence and investigation progress. - [SAFE]: The skill explicitly defines its scope as investigation, stating that "agreement is fuel for exploring, not a green light" and that only the user naming a concrete change authorizes making modifications to the project.
Audit Metadata