explore-unknowns
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external codebase files during the 'Scan' and 'Sweep' phases, which serves as a potential surface for indirect prompt injection from malicious content within those files. * Ingestion points: The agent reads local files in the target project directory (referenced in stage-1-known-knowns.md and stage-4-unknown-unknowns.md). * Boundary markers: No specific delimiters or 'ignore instructions' warnings are defined for the file-reading process. * Capability inventory: The skill uses file-read tools and spawns subagents to process the codebase. * Sanitization: The skill relies on the underlying model's safety protocols for processing untrusted text.
- [SAFE]: The skill enforces a security policy for generated HTML artifacts, requiring them to be self-contained with inline assets and no external network requests, which mitigates data exfiltration risks.
- [SAFE]: The 'Preference Checkpoint' delegation system requires explicit user opt-in and provides full disclosure for every decision made by the agent, ensuring user oversight and preventing unauthorized autonomous actions.
Audit Metadata