lov-xbti-gallery

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display content from external, community-provided repositories (specified in step 3 of the Workflow in SKILL.md). This creates a surface for malicious instructions to influence the agent's behavior.
  • Ingestion points: Data is fetched from the cases directories of external repositories using the gh CLI or via browser retrieval.
  • Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore' instructions for the external content when displaying test names, descriptions, or introductions to the user.
  • Capability inventory: The agent has the capability to write to a local profile file using scripts/profile_store.py, execute search and file operations, use the gh CLI, and open URLs in a browser.
  • Sanitization: There are no instructions in the skill body to sanitize, escape, or validate the content retrieved from external sources before it is interpolated into the agent's context or displayed to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:09 PM
Security Audit — agent-trust-hub — lov-xbti-gallery