settle
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill mandates the ingestion and analysis of untrusted data sources to resolve technical decisions, creating an attack surface for indirect prompt injection.
- Ingestion points: The method requires inspecting "code, tests, configuration, project precedent," "authoritative documentation," and "standards" (SKILL.md).
- Boundary markers: There are no instructions to use delimiters or ignore potentially malicious instructions embedded within the analyzed data sources.
- Capability inventory: The agent is instructed to "Apply the decision when the active task grants write authority," which involves modifying the file system based on potentially manipulated technical evidence.
- Sanitization: The skill does not define any sanitization, filtering, or validation steps for the evidence collected from the repository or external documentation.
Audit Metadata