brain

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data snippets retrieved through the brain_search tool, which presents a potential surface for indirect prompt injection from the contents of the knowledge base.
  • Ingestion points: Snippets returned by the mcp__governed-brain__brain_search tool as described in the search workflow in SKILL.md.
  • Boundary markers: While explicit delimiters for data snippets are not defined in the instructions, the skill enforces strict grounding by requiring qmd:// citations for every claim and synthesis based only on returned snippets.
  • Capability inventory: The skill utilizes the mcp__governed-brain__brain_search tool. Prerequisite documentation in SKILL.md and references/runtime-contract.md mentions a requirement for a local qmd binary on the system path for local mode operations.
  • Sanitization: The instructions provide a strict multi-step retrieval process and mandate that the agent must refuse to answer if no results are found, effectively preventing the use of unverified general knowledge.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 05:13 PM
Security Audit — agent-trust-hub — brain