mobile
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of untrusted user task descriptions and the analysis of existing application code during audits.\n
- Ingestion points: The skill accepts plain-language task descriptions from the user to resolve development modes (in
SKILL.md) and reads existing project files during accessibility and store audits (inreferences/audit.md).\n - Boundary markers: There are no specific delimiters or "ignore embedded instructions" warnings defined to separate user-provided content or external file data from the agent's core instructions.\n
- Capability inventory: The skill utilizes powerful system tools including
bash,run_command,write_to_file,replace_file_content, andgrep_search(as defined in theagents/openai.yamlconfiguration).\n - Sanitization: The procedure does not include explicit validation, filtering, or escaping of the content ingested from user prompts or project files before it is processed by the agent.
Audit Metadata