spine-curate
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project knowledge, candidate materials, and source evidence which could potentially contain malicious instructions.
- Ingestion points: The skill instructions in
SKILL.mdand the subagent briefs inreferences/involve readingAGENTS.md, candidate artifacts, and external source evidence. - Boundary markers: No explicit delimiters or instructions to ignore embedded prompts are provided in the prompt templates for the data being analyzed.
- Capability inventory: The skill is authorized to edit documentation and the knowledge index (
SKILL.md), although it requires explicit approval. - Sanitization: No sanitization, filtering, or validation of the external content is described before it is processed by the agent.
- Mitigation: The risk is mitigated by the design of the skill as a 'manual maintainer capability' which requires 'explicit maintainer approval' before any proposed changes are applied to the filesystem.
Audit Metadata