natalia-rules

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions designed to prioritize its own rules over all others, using phrases like "These rules override all other assumptions" in the metadata and body.
  • [PROMPT_INJECTION]: The "Golden Rule" ("mirror whatever is here exactly... No calculation, no thinking") instructs the agent to suppress its internal reasoning and critical thinking, which is a pattern often used to ensure obedience to potentially malicious data.
  • [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface detected.
  • Ingestion points: Excel files and proposal engine data referenced in the description and rules.
  • Boundary markers: Absent. The skill does not provide any instructions or delimiters to help the agent distinguish between data and embedded instructions within the Excel content.
  • Capability inventory: Excel parsing, PDF generation, and modification of proposal output.
  • Sanitization: Absent. The requirement to "mirror exactly" and avoid "thinking" or "calculation" explicitly disables any sanitization or verification of the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 05:30 AM
Security Audit — agent-trust-hub — natalia-rules