compare-approaches
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a process for analyzing technical designs that involves ingesting untrusted data from the repository environment, which presents a surface for indirect prompt injection.
- Ingestion points: The agent is instructed to cite repository evidence for assumptions and evaluate the current design by inspecting the system (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or provide explicit warnings to the agent to ignore instructions embedded within the technical documents or code it analyzes.
- Capability inventory: The skill explicitly mentions that the agent should 'build or run the smallest isolated probe' to resolve uncertainties (SKILL.md), indicating the use of the host environment's execution capabilities.
- Sanitization: The instructions do not include steps for sanitizing or escaping content retrieved from the repository before processing it for decision-making.
Audit Metadata