prfaq-beagle
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from both external web research and local document analysis, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill reads 'report.md' files generated by the artifact-analysis and web-research companion skills into the active context during the Ignition stage (SKILL.md).
- Boundary markers: The instructions do not specify the use of strong delimiters or 'ignore embedded instructions' warnings for the content read from these reports, though it does organize findings into 'Reasoning' blocks.
- Capability inventory: The skill has the capability to write files (prfaq.md, brief.md) to the local filesystem and to trigger other agent skills like brainstorm-beagle.
- Sanitization: No explicit sanitization or filtering logic is defined for the external data before it is interpolated into the prompts used for coaching and verdict generation.
Audit Metadata