craft-diorama-still-life

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external article content to extract metaphors and titles. 1. Ingestion points: Data is read from user-provided local file paths (SKILL.md). 2. Boundary markers: Absent; the skill does not use specific delimiters to isolate source text from instructions. 3. Capability inventory: File system access for reading source documents and writing output Markdown files (SKILL.md). 4. Sanitization: Absent; extracted content is interpolated directly into prompt templates.
  • [COMMAND_EXECUTION]: The agent is instructed to perform file system operations, specifically reading article content and writing generated prompt files. These are core functional requirements of the skill's described purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:12 AM
Security Audit — agent-trust-hub — craft-diorama-still-life