calm-down
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill provides instructional overrides (e.g., 'Immediately cease all file edits', 'Do not apologize') that are triggered by user frustration. These are intended for alignment and behavioral control rather than bypassing safety filters.
- [PROMPT_INJECTION]: The protocol creates a surface for indirect prompt injection by instructing the agent to ingest free-form user input ('rambles') and summarize it for subsequent action.
- Ingestion points: The user's messy or free-form feedback described in Step 2 of
SKILL.md. - Boundary markers: The skill specifies a numbered list format for the summary but does not mandate the use of XML tags or other delimiters to isolate user-provided content from agent instructions.
- Capability inventory: The agent retains its standard toolset (file editing, command execution) throughout the process.
- Sanitization: No specific sanitization or filtering logic is suggested for the user-provided text before it is summarized and confirmed.
Audit Metadata