cold-read
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the refactoring of documentation files which could serve as a vector for indirect prompt injection if the processed content contains malicious instructions.\n
- Ingestion points: The agent reads and processes external documentation files including READMEs, SKILL.md, and runbooks.\n
- Boundary markers: The instructions do not define delimiters or specific warnings to ignore embedded instructions within the source files.\n
- Capability inventory: The skill uses text generation and file-writing capabilities to perform documentation refactoring.\n
- Sanitization: There are no defined processes for escaping or validating the content of the files being refactored.
Audit Metadata