matt-grilling
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-supplied plans and decisions without the use of boundary markers or sanitization protocols. This creates a surface for indirect prompt injection, where instructions embedded within the user's input could be misinterpreted by the agent as legitimate system instructions.\n- [COMMAND_EXECUTION]: The instructions direct the agent to 'dispatch a sub-agent' to gather facts from the environment and filesystem autonomously rather than asking the user. This automated capability increases the potential impact of an indirect prompt injection, as the agent may be manipulated into accessing sensitive files or executing unintended commands during its fact-finding process.
Audit Metadata