lov-xbti-gallery
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display content from external, community-provided repositories (specified in step 3 of the Workflow in
SKILL.md). This creates a surface for malicious instructions to influence the agent's behavior. - Ingestion points: Data is fetched from the
casesdirectories of external repositories using theghCLI or via browser retrieval. - Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore' instructions for the external content when displaying test names, descriptions, or introductions to the user.
- Capability inventory: The agent has the capability to write to a local profile file using
scripts/profile_store.py, execute search and file operations, use theghCLI, and open URLs in a browser. - Sanitization: There are no instructions in the skill body to sanitize, escape, or validate the content retrieved from external sources before it is interpolated into the agent's context or displayed to the user.
Audit Metadata