brain
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data snippets retrieved through the
brain_searchtool, which presents a potential surface for indirect prompt injection from the contents of the knowledge base. - Ingestion points: Snippets returned by the
mcp__governed-brain__brain_searchtool as described in the search workflow inSKILL.md. - Boundary markers: While explicit delimiters for data snippets are not defined in the instructions, the skill enforces strict grounding by requiring
qmd://citations for every claim and synthesis based only on returned snippets. - Capability inventory: The skill utilizes the
mcp__governed-brain__brain_searchtool. Prerequisite documentation inSKILL.mdandreferences/runtime-contract.mdmentions a requirement for a localqmdbinary on the system path for local mode operations. - Sanitization: The instructions provide a strict multi-step retrieval process and mandate that the agent must refuse to answer if no results are found, effectively preventing the use of unverified general knowledge.
Audit Metadata