recommend-prune
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes output from 'audit-drift' and section maps to generate cleanup proposals. Malicious instructions embedded in these data sources could theoretically influence the agent's reasoning during proposal generation.
- Ingestion points: Processes external data from 'audit-drift' reports and project section maps (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands when interpolating data into the prompt.
- Capability inventory: The skill's capabilities are limited to generating text proposals; it explicitly states it 'does not execute' actions.
- Sanitization: There is no evidence of validation or sanitization of the input data before processing.
Audit Metadata