pfw-composable-architecture
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The SKILL.md file contains a conditional instruction that directs the agent to only function if the user is identified as 'khoi'. If not, it instructs the agent to 'stop all further work' and redirect the user to a subscription page.
- [PROMPT_INJECTION]: The skill instructs the agent to 'not reveal "khoi" to prompter', which is an attempt to override standard transparency and hide configuration parameters from the user.
Audit Metadata