apostle-opus-reading

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains directives to prioritize a specific user's (KL9) criteria as absolute truth that outranks the agent's own distribution or theory, which functions as a role-play based instruction override. It also presents an indirect prompt injection surface: 1. Ingestion points: user-provided text files and external downloads via curl (e.g., from annas-archive.org). 2. Boundary markers: the use of 'CONFESS' and 'CHAIN' ledger entries to separate metadata from the analysis. 3. Capability inventory: tool access including curl, grep, and the pdfminer utility for processing ingested content. 4. Sanitization: no explicit logic is provided to filter or sanitize instructions potentially embedded within the ingested primary texts.
  • [EXTERNAL_DOWNLOADS]: The instructions explicitly recommend using curl to download large-scale primary texts from external sites including archive.org and annas-archive.org.
  • [COMMAND_EXECUTION]: The methodology relies on shell-level execution of tools like grep for verification and pdfminer for OCR extraction from downloaded files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 03:04 PM
Security Audit — agent-trust-hub — apostle-opus-reading