structure-agenda
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection. 1. Ingestion points: The agent reads DISCOVERY.json (SKILL.md) and is instructed to auto-fetch and summarize external source URLs provided by the user (ITERATION.md). 2. Boundary markers: No delimiters or explicit instructions to ignore embedded commands are specified for the ingested content. 3. Capability inventory: The skill writes to AGENDA.md and PROJECT.json (DRAFT_AGENDA.md) and triggers a downstream generate-slides phase. 4. Sanitization: No evidence of escaping or filtering of external content is present.
Audit Metadata