product-launch-war-room

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests data from external sources and persona files to inform its simulated debate, which could contain instructions designed to manipulate the agent's output or tool usage.
  • Ingestion points: The skill reads data from the personas/ directory and gathers information via the WebSearch, WebFetch, and icp-deep-scanner tools (Step 2).
  • Boundary markers: There are no instructions to wrap untrusted data in delimiters or explicit warnings for the agent to ignore instructions embedded within the processed content.
  • Capability inventory: The skill utilizes powerful tools across its instructions, including Bash for shell execution, Write for file modifications, and Agent for spawning sub-agents via the /agent-army command.
  • Sanitization: The skill lacks mechanisms for sanitizing or validating external content before it is interpolated into the agent's reasoning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — product-launch-war-room