xb-add-world-sensing

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Consideration: The skill establishes patterns for ingesting data from the physical environment (such as object recognition and scene context). This creates a potential surface where adversarial content in the physical world could influence the agent's behavior.\n
  • Ingestion points: The references/branches.md file describes signals for object detection and agent-facing context that enter the application state.\n
  • Boundary markers: The current instructions do not specify explicit delimiters or "ignore" instructions for sensor-derived data.\n
  • Capability inventory: The skill focuses on application state and rendering updates within the XR Blocks framework, without suggesting sensitive system-level capabilities or unauthorized network access.\n
  • Sanitization: Guidance for sanitizing or filtering recognized object metadata or scene descriptions is not explicitly provided in these instructions.\n- External Processing and Credential Management: The skill appropriately notes that using certain backends for object detection involves off-device processing and requires credential acceptance. This highlights a standard architectural consideration for developers regarding data privacy and secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 07:30 AM
Security Audit — agent-trust-hub — xb-add-world-sensing