monologue-context
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-generated content from the Monologue application, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: External data is ingested through the search_notes and get_note tools described in SKILL.md.
- Boundary markers: The instructions lack specific delimiters or guardrails to help the agent distinguish between note content and its own system instructions.
- Capability inventory: The skill environment includes note retrieval and synthesis capabilities; however, it lacks network or file-write permissions.
- Sanitization: There is no mention of sanitization, filtering, or validation of the fetched note content before it is processed by the agent.
- [NO_CODE]: The skill package does not contain any executable scripts or binary files, relying solely on markdown instructions.
Audit Metadata