bake-the-brief
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by instructing the agent to ingest and follow instructions from external context files.
- Ingestion points: The agent is directed in
SKILL.mdto read 'brief' and 'close-out' files from the repository or session context. - Boundary markers: No specific delimiters or instructions to ignore embedded commands within the ingested content are provided.
- Capability inventory: While the skill itself defines no specific tools, the ingested content could influence the agent's general tool usage.
- Sanitization: No content filtering or validation logic is present for the ingested files.
- [EXTERNAL_DOWNLOADS]: The skill references external documentation resources for the design framework.
- Evidence: Links to the author's GitHub repository (
github.com/iruhdam1/prefix-first-design) and personal website (madhurimaram.com) are included in the footer ofSKILL.md.
Audit Metadata