idea
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes markdown files from the
docs/ideas/directory. If these files contain malicious instructions, they could potentially influence the agent's behavior during the 'List' or 'Validate' operations. - Ingestion points: Reads all files in the
docs/ideas/directory. - Boundary markers: None mentioned for file reading or parsing.
- Capability inventory: The skill has file system write access and can execute shell commands to run prototypes.
- Sanitization: No explicit sanitization or instruction to ignore embedded commands is present when displaying the idea list or performing the validation grill.
- [DYNAMIC_EXECUTION]: The 'Prototype' operation involves the agent generating 'throwaway code' and executing it using the project's existing runners to answer logic questions.
- Pattern: Writing and executing scripts in the
prototypes/folder or with aproto-prefix. - Mitigation: The instructions explicitly state that prototypes should have no persistence (memory only), be throwaway from day one, and skip non-essential polish like error handling, which reduces the complexity of the execution environment.
Audit Metadata