xb-add-world-sensing
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Consideration: The skill establishes patterns for ingesting data from the physical environment (such as object recognition and scene context). This creates a potential surface where adversarial content in the physical world could influence the agent's behavior.\n
- Ingestion points: The
references/branches.mdfile describes signals for object detection and agent-facing context that enter the application state.\n - Boundary markers: The current instructions do not specify explicit delimiters or "ignore" instructions for sensor-derived data.\n
- Capability inventory: The skill focuses on application state and rendering updates within the XR Blocks framework, without suggesting sensitive system-level capabilities or unauthorized network access.\n
- Sanitization: Guidance for sanitizing or filtering recognized object metadata or scene descriptions is not explicitly provided in these instructions.\n- External Processing and Credential Management: The skill appropriately notes that using certain backends for object detection involves off-device processing and requires credential acceptance. This highlights a standard architectural consideration for developers regarding data privacy and secret management.
Audit Metadata