idea-refine
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted user input and scans local project files to provide context for ideation. This is a functional requirement for the skill's purpose. * Ingestion points: The skill reads data from $ARGUMENTS and uses tools like Glob, Grep, and Read to ingest file content from the local directory. * Boundary markers: There are no specific delimiters used to isolate processed data from the agent's core instructions. * Capability inventory: The skill uses file-read tools and can write output files to the docs/ideas/ directory with user confirmation. * Sanitization: The skill does not implement specific sanitization for ingested content before it is processed.
Audit Metadata