apostle-opus-reading
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains directives to prioritize a specific user's (KL9) criteria as absolute truth that outranks the agent's own distribution or theory, which functions as a role-play based instruction override. It also presents an indirect prompt injection surface: 1. Ingestion points: user-provided text files and external downloads via
curl(e.g., fromannas-archive.org). 2. Boundary markers: the use of 'CONFESS' and 'CHAIN' ledger entries to separate metadata from the analysis. 3. Capability inventory: tool access includingcurl,grep, and thepdfminerutility for processing ingested content. 4. Sanitization: no explicit logic is provided to filter or sanitize instructions potentially embedded within the ingested primary texts. - [EXTERNAL_DOWNLOADS]: The instructions explicitly recommend using
curlto download large-scale primary texts from external sites includingarchive.organdannas-archive.org. - [COMMAND_EXECUTION]: The methodology relies on shell-level execution of tools like
grepfor verification andpdfminerfor OCR extraction from downloaded files.
Audit Metadata