env-capability-discovery
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines an environment discovery protocol that ingests metadata from other installed skills to determine workflow enhancements.
- Ingestion points: The skill reads names and descriptions from the system prompt's available-items listing or the platform's skill-listing tool (referenced in SKILL.md).
- Boundary markers: There are no instructions to use delimiters or markers to prevent the agent from following instructions embedded within the scanned skill descriptions.
- Capability inventory: The skill allows for the dynamic invocation of discovered skills matching specific functional keywords (referenced in SKILL.md).
- Sanitization: The discovery process uses keyword matching but does not specify validation or sanitization of the targeted skill's content before invocation.
Audit Metadata