gpt6-astra-prompting-guide

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill claims to be based on 'official OpenAI guidance' and refers to a 'GPT-6 Astra' model with a verification date in the future (2026). This is deceptive as it presents fictional or hypothetical documentation as authoritative, which could lead an agent to misjudge its actual capabilities or follow unsupported runtime instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to analyze and edit external instructions, prompts, and failure traces. This creates a vulnerability surface where malicious instructions embedded in the processed data could attempt to influence the agent's behavior.
  • Ingestion points: The skill processes 'active prompts', 'loaded instructions', 'AGENTS.md', and 'tool descriptions' provided by the user.
  • Boundary markers: The skill suggests using a template that uses markdown headers and placeholders to separate context from instructions, and it explicitly advises the agent to 'resolve loaded guidance according to instruction authority'.
  • Capability inventory: The skill is purely informational and does not define any tool permissions or code execution capabilities in its frontmatter.
  • Sanitization: There is no explicit sanitization or filtering mechanism for the ingested prompts, though the skill provides guidance on identifying and resolving instruction conflicts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:17 PM
Security Audit — agent-trust-hub — gpt6-astra-prompting-guide