causal-design

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted research data from local project files, creating a surface for indirect prompt injection where malicious instructions in a research paper could influence agent behavior. 1. Ingestion points: Reads files from user-specified project paths, including .tex files and estimation scripts in 'Audit' mode, as well as user interview data. 2. Boundary markers: The skill lacks clear delimiters or 'ignore embedded instructions' warnings when interpolating ingested data into the 'domain-reviewer' sub-agent's prompt context. 3. Capability inventory: The agent possesses capabilities for file modification ('Write', 'Edit'), project navigation ('Glob', 'Grep'), and sub-agent delegation ('Task'). 4. Sanitization: No sanitization, escaping, or validation of the content extracted from external files is performed before it is integrated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 06:17 AM
Security Audit — agent-trust-hub — causal-design