pal
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses highly coercive and mandatory language to override the agent's decision-making process regarding tool execution and model selection.
- Evidence: The
<critical>section inSKILL.mduses phrases such as "NEVER stop a workflow", "ALWAYS increment", "TASK INVALIDATION: Incomplete workflows result in immediate task rejection", and "NO EXCEPTIONS". - Evidence: The skill mandates the use of a specific model string (
anthropic/claude-opus-4.6) for all tool calls, which is a non-standard version and attempts to dictate the agent's identity or execution environment. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external, untrusted code for analysis, debugging, and refactoring, creating a surface for indirect prompt injection attacks.
- Ingestion points: The
relevant_filesparameter across all tools inSKILL.mdandreferences/allows the agent to read arbitrary project files. - Boundary markers: Absent. There are no instructions or requirements to delimit or wrap the content of the analyzed files to prevent the agent from executing instructions embedded within them.
- Capability inventory: The skill includes tools for code analysis (
mcp__zen__analyze), debugging (mcp__zen__debug), planning (mcp__zen__planner), and refactoring (mcp__zen__refactor). - Sanitization: Absent. The instructions do not mention sanitizing or validating the contents of the files before processing them.
Audit Metadata