behavioral-modes
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill uses specific triggers and commands (e.g., '/debug', 'how does') to switch AI behavior modes. These instructions guide the agent's persona and output formatting based on input text.
- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by design, as it involves analyzing external files for tasks like debugging or auditing.
- Ingestion points: Untrusted data enters the agent context through the 'Read' and 'Grep' tools when inspecting files in DEBUG, REVIEW, or TEACH modes.
- Boundary markers: The skill lacks explicit instructions or delimiters to isolate file content from the agent's internal operational instructions, increasing the risk of the agent following instructions embedded in files.
- Capability inventory: The skill's primary capabilities are limited to file system read access ('Read', 'Glob', 'Grep'), which restricts the potential impact of an injection to information disclosure or persona manipulation within the current session.
- Sanitization: There is no evidence of input validation, escaping, or filtering of content read from external files.
- [NO_CODE]: The skill is composed entirely of markdown instructions and metadata with no accompanying executable code or scripts.
Audit Metadata