causal-inference-root-cause

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze potentially untrusted data provided by users, such as system logs, error messages, and incident descriptions. This creates an attack surface where an adversary could embed malicious instructions within the data being analyzed to influence the agent's reasoning or output. However, the risk is significant only if the agent has high-privilege tools, whereas this skill primarily focuses on text generation and markdown documentation.\n
  • Ingestion points: User-provided descriptions of 'effects' and 'hypotheses' in the root cause analysis workflow (SKILL.md, Step 1 and 2).\n
  • Boundary markers: Absent; the instructions do not suggest using delimiters or warnings to ignore instructions embedded in the data.\n
  • Capability inventory: The skill involves text analysis, hypothesis generation, and creating markdown files; no network operations, subprocess executions, or dynamic code loading are present in the provided files.\n
  • Sanitization: Absent; no methods for escaping or validating the external input are defined in the methodology.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 09:54 AM
Security Audit — agent-trust-hub — causal-inference-root-cause