santa-method
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data (identified as
task_specandoutput) by interpolating it directly into a prompt template for sub-agents (Reviewer B and Reviewer C). This creates a vulnerability where the content being reviewed could attempt to override the reviewer's instructions. - Ingestion points: The variables
task_specandoutputare ingested inSKILL.mdduring the Phase 2 (Check It Twice) and Phase 4 (Fix Cycle) logic. - Boundary markers: The prompt template uses markdown headers (
## Task Specification,## Output Under Review) as delimiters. However, it lacks explicit instructions for the reviewer agents to ignore or disregard any instructions contained within theoutputdata. - Capability inventory: The skill utilizes sub-agent spawning (
Agenttool), automated correction (fix_agent.execute), and a terminal shipping action (ship). - Sanitization: No evidence of sanitization, escaping, or schema validation is present for the
outputstring before it is interpolated into theREVIEWER_PROMPT.
Audit Metadata