loop-me
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and writing to files within the local workspace, creating a surface where untrusted data could influence agent behavior.
- Ingestion points: The skill reads context from NOTES.md and workflows/*.md (SKILL.md).
- Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between file content and agent instructions.
- Capability inventory: The skill allows the agent to read, create, edit, and delete files in the workflows/ directory (SKILL.md).
- Sanitization: There are no requirements for the agent to sanitize or validate the content retrieved from the workspace before processing it.
Audit Metadata