santa-method

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data (identified as task_spec and output) by interpolating it directly into a prompt template for sub-agents (Reviewer B and Reviewer C). This creates a vulnerability where the content being reviewed could attempt to override the reviewer's instructions.
  • Ingestion points: The variables task_spec and output are ingested in SKILL.md during the Phase 2 (Check It Twice) and Phase 4 (Fix Cycle) logic.
  • Boundary markers: The prompt template uses markdown headers (## Task Specification, ## Output Under Review) as delimiters. However, it lacks explicit instructions for the reviewer agents to ignore or disregard any instructions contained within the output data.
  • Capability inventory: The skill utilizes sub-agent spawning (Agent tool), automated correction (fix_agent.execute), and a terminal shipping action (ship).
  • Sanitization: No evidence of sanitization, escaping, or schema validation is present for the output string before it is interpolated into the REVIEWER_PROMPT.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — santa-method