qstack-explain-for
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves processing and rewriting the previous assistant response, which serves as an entry point for untrusted data.
- Ingestion points: The
SKILL.mdfile identifies the "immediately previous assistant answer" as the target for rewriting. - Boundary markers: The instructions do not define boundary markers to isolate the input data from the skill's own logic.
- Capability inventory: No executable tools or system capabilities are available to the skill; it explicitly forbids calling tools or adding new facts.
- Sanitization: There is no evidence of input sanitization or filtering logic to prevent obedience to instructions embedded within the processed text.
Audit Metadata