credo-paper-plan

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-controlled data in the form of paper drafts to provide critiques, which presents a surface for indirect prompt injection attacks. 1. Ingestion points: The agent is instructed to read and evaluate paper drafts provided by the user in the 'Critique a draft against the plan' section. 2. Boundary markers: The instructions do not define specific delimiters or guidelines for the agent to ignore potentially malicious instructions embedded within the user's prose. 3. Capability inventory: The skill specifies instructional logic for planning and critiquing but does not include scripts that perform high-risk operations like network exfiltration or direct command execution. 4. Sanitization: No sanitization, filtering, or validation steps are prescribed for the ingested draft content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 11:51 AM
Security Audit — agent-trust-hub — credo-paper-plan