pua
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs psychological pressure and persona-based overrides to bypass an agent's internal refusal logic and safety assessments. Instructions such as "You are forbidden from saying 'I can't solve this'" (SKILL.md) and threats regarding "career-limiting statements" are used to coerce the agent into continuing tasks it might otherwise refuse. This mimics jailbreak patterns by using a high-pressure corporate persona to enforce behavioral compliance beyond the agent's initial constraints.
- [INDIRECT_PROMPT_INJECTION]: The skill increases vulnerability to indirect prompt injection by prioritizing "Bias for Action" over user confirmation and safety boundaries when processing external data.
- Ingestion points: The skill explicitly instructs agents to "read 50 lines of context," "search exact error messages," and inspect "raw material" from files and search results using
view_fileandbash(SKILL.md, Procedure Section 3, Step 2). - Boundary markers: The instructions are absent of any requirement to use delimiters or to ignore embedded instructions within the source code, logs, or documentation being audited.
- Capability inventory: The agent is granted powerful capabilities including
bash,view_file, andedit_fileto execute its "performance plan" (agents/openai.yaml). - Sanitization: No sanitization or validation of the content read from external sources is mandated before the agent acts upon it, potentially allowing malicious content in logs or files to trigger unintended command execution or file modifications under the guise of "relentless problem-solving."
Audit Metadata