qstack-explain-for

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves processing and rewriting the previous assistant response, which serves as an entry point for untrusted data.
  • Ingestion points: The SKILL.md file identifies the "immediately previous assistant answer" as the target for rewriting.
  • Boundary markers: The instructions do not define boundary markers to isolate the input data from the skill's own logic.
  • Capability inventory: No executable tools or system capabilities are available to the skill; it explicitly forbids calling tools or adding new facts.
  • Sanitization: There is no evidence of input sanitization or filtering logic to prevent obedience to instructions embedded within the processed text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:27 AM