jobs
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting data from active research processes and scheduled tasks. Ingestion points: Data from 'pi-processes', 'pi-schedule-prompt', and subagent tasks are brought into the agent's context during inspection. Boundary markers: There are no explicit delimiters or boundary instructions provided in the skill file to isolate or ignore potentially malicious instructions within the background task data. Capability inventory: The agent has the capability to read and process the content of these background tasks. Sanitization: The skill configuration does not include any mechanisms for sanitizing or validating the content of the tasks before processing.
Audit Metadata