document-review
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface by ingesting and processing untrusted content from document files during its review workflow.\n
- Ingestion points: The agent reads document files from specified paths or standard directories like docs/brainstorms/ in Step 1 of SKILL.md.\n
- Boundary markers: The instructions do not define explicit delimiters or 'ignore' headers to isolate processed document content from agent instructions.\n
- Capability inventory: The skill has the capability to modify files and interact with the user via authorized platform tools like AskUserQuestion (SKILL.md Step 6).\n
- Sanitization: No explicit sanitization, filtering, or validation of the document content is specified before the analysis phase.
Audit Metadata