museum-art

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong behavioral overrides, instructing the agent to 'execute it exactly as written' and labeling a specific file as the 'authoritative playbook.' This is a technique used to bypass default agent constraints or safety guidelines by fixating the agent on a specific set of instructions.
  • [PROMPT_INJECTION]: The skill references external rule files such as .agents/rules/cog.md and dynamically computed subagent paths in .agents/agents/<name>.md. This creates an indirect prompt injection surface where the behavior of the agent is determined by files external to the skill's primary logic, which could contain malicious or unvetted instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 12:21 PM
Security Audit — agent-trust-hub — museum-art