peer
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an agent role that processes external 'packets' of instructions, creating a surface for potential indirect prompt injection.
- Ingestion points: Task 'packets' described in SKILL.md.
- Boundary markers: The instructions mandate restating the packet intent and following a specific six-step execution process (SKILL.md) to maintain task boundaries.
- Capability inventory: The agent is authorized to implement, test, and operate on files, which grants it substantial capabilities over the local environment (SKILL.md).
- Sanitization: The agent is explicitly instructed to reject any packet requesting access to WORKSPACE_PROTOCOL.md or config.model (SKILL.md, agents/openai.yaml).
Audit Metadata