skills/felipeangeli/skills/pal/Gen Agent Trust Hub

pal

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses highly coercive and mandatory language to override the agent's decision-making process regarding tool execution and model selection.
  • Evidence: The <critical> section in SKILL.md uses phrases such as "NEVER stop a workflow", "ALWAYS increment", "TASK INVALIDATION: Incomplete workflows result in immediate task rejection", and "NO EXCEPTIONS".
  • Evidence: The skill mandates the use of a specific model string (anthropic/claude-opus-4.6) for all tool calls, which is a non-standard version and attempts to dictate the agent's identity or execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external, untrusted code for analysis, debugging, and refactoring, creating a surface for indirect prompt injection attacks.
  • Ingestion points: The relevant_files parameter across all tools in SKILL.md and references/ allows the agent to read arbitrary project files.
  • Boundary markers: Absent. There are no instructions or requirements to delimit or wrap the content of the analyzed files to prevent the agent from executing instructions embedded within them.
  • Capability inventory: The skill includes tools for code analysis (mcp__zen__analyze), debugging (mcp__zen__debug), planning (mcp__zen__planner), and refactoring (mcp__zen__refactor).
  • Sanitization: Absent. The instructions do not mention sanitizing or validating the contents of the files before processing them.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — pal