blind
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted user-supplied 'targets' (such as code, plans, or documents) and passes them to subagents for analysis. Instructions hidden within these targets could attempt to influence the audit results. \n
- Ingestion points: The skill reads data from the 'target' argument, the current conversation history, and primary source files or logs specified in SKILL.md. \n
- Boundary markers: The skill uses a 'ground-truth brief' to scope subagents, but the target content itself is not isolated with explicit delimiters or instructions to disregard embedded commands. \n
- Capability inventory: The skill is capable of reading and writing files and invoking subagents via platform tools like the Agent and Skill tools. \n
- Sanitization: The dispatcher is instructed to fact-check findings against primary sources to ensure factual accuracy and prevent model hallucination or drift.
Audit Metadata