nd-setshift
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by instructing the agent to read and summarize potentially untrusted data from local error logs and session notes. \n
- Ingestion points: The instructions specify reading
ERRORS.md, debug logs, and prior session notes to summarize past attempts. \n - Boundary markers: No specific delimiters or instructions to ignore embedded instructions are provided for separating log content from agent instructions. \n
- Capability inventory: The skill relies on the agent's general file-reading and reasoning capabilities to process the logs. \n
- Sanitization: No sanitization or filtering of the log content is prescribed before the agent summarizes it. \n
- Note: This functionality is intrinsic to the skill's purpose of avoiding repetitive failures and is considered a safe operational pattern.
Audit Metadata