ico-your-internals
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted Markdown files from a target directory and executes user-defined prompts from a question bank.
- Ingestion points: The
scripts/run.shscript identifies and ingests all Markdown files within a user-specified--targetdirectory. Thescripts/ask-loop.pyscript reads and executes questions defined in an external YAML--bankfile. - Boundary markers: The
SKILL.mdinstructions explicitly define the target documents as read-only and restrict writes to a dedicated local cache directory (~/.cache/ico-your-internals/). - Capability inventory: The skill possesses the ability to execute shell commands (to run the
icoCLI) and write files to both the local cache and the project repository (for rendering results). - Sanitization: The
scripts/render-summary.pyscript utilizes a regex-basedSECRET_PATTERNSfilter to detect and redact API keys (e.g., Anthropic keys) and authorization tokens from the generated public evidence bundle.
Audit Metadata