before-after
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from
jtbd.jsonfiles to automatically map and generate transformation grids, which could be exploited if the source files are attacker-controlled. \n - Ingestion points: Instructions in
SKILL.md(Step 1) direct the agent to extract dimensions from specific fields injtbd.json(e.g.,switch_forces.push,problem.what_hurts,needs.functional[]). \n - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat this ingested content strictly as data or to ignore any malicious instructions embedded within it. \n
- Capability inventory: The skill has the capability to write files to the local filesystem (
~/jtbd) and invoke external image generation tools (/nano-bananaor ChatGPT API). \n - Sanitization: No evidence of validation, schema enforcement, or escaping is present for the data read from the local corpus files.
Audit Metadata