unpack
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by design. It is instructed to ingest and interpret potentially untrusted data like codebases, documents, and jargon-heavy passages. Furthermore, the skill has a high-capability downstream function: translating user intent into precise instructions for other agents, including naming specific files and changes. The lack of explicit boundary markers or instructions to disregard embedded commands in the source material means the agent could inadvertently follow instructions hidden in the text it is analyzing. (Ingestion points: SKILL.md, summarize.md; Boundary markers: Absent; Capability inventory: Precise instruction generation for agents; Sanitization: Absent).
Audit Metadata