principle-cultivation
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection (Category 8) by processing untrusted data into its principle lineage. Ingestion points: Data enters the agent's context via the
<question|paths>and<path...>arguments in the/principle-cultivation researchand/principle-cultivation extractcommands (SKILL.md). Boundary markers: The skill relies on structured templates (e.g., research-template.md) but lacks explicit delimiters or specific instructions to disregard embedded commands in the source material. Capability inventory: The skill instructs the agent to perform file system writes and directory management within theprinciples/folder, including updating the semantic source fileSEQUENCE.md. Sanitization: No validation or sanitization routines are specified for the input data before it is incorporated into the principle artifacts. - [NO_CODE]: This is a no-code skill where logic is defined through instructions and templates rather than executable scripts.
Audit Metadata