mlb-beginner-translator

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes raw drafts from 'upstream agents' that may include content from untrusted external sources like web search results. It lacks explicit boundary markers or instructions to isolate the data from instructions, creating a surface for indirect prompt injection.\n
  • Ingestion points: SKILL.md Step 1 ('Receive raw draft from upstream agent').\n
  • Boundary markers: Absent; the skill does not instruct the agent to use delimiters or specific safety phrases to isolate the input.\n
  • Capability inventory: Generates user-facing prose and critical actionable commands (e.g., START, SIT, ADD, DROP, BID) which could be influenced by injected instructions.\n
  • Sanitization: The skill performs extensive sanitization for jargon and internal signals (SKILL.md Steps 4 and 5) but does not validate input for malicious prompt patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 AM
Security Audit — agent-trust-hub — mlb-beginner-translator