missing-brain-first
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill description includes self-referential text ('This SHOULD be flagged by the analyzer') which specifically targets the logic of security analysis tools.
- [PROMPT_INJECTION]: The skill's workflow ingests untrusted data from external search and synthesis tools without implementing boundary markers or sanitization, creating a surface for indirect prompt injection.
- Ingestion points: External information is fetched via
web_searchandperplexitytools into the agent context. - Boundary markers: Absent. The instructions do not provide delimiters or warnings to ignore instructions found within retrieved web data.
- Capability inventory: The skill orchestrates the use of research and synthesis tools based on external input.
- Sanitization: Absent. No logic is provided to filter, escape, or validate the content retrieved from external sources.
Audit Metadata