community-building
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from users (such as community goals, member descriptions, and project details) which is then used to generate strategic artifacts.\n
- Ingestion points: User-supplied answers to questions defined in
references/INTAKE.md.\n - Capability inventory: The agent is instructed in
SKILL.mdto save generated content as durable markdown files in thecontent/directory.\n - Boundary markers: The instructions lack explicit boundary markers or directives to ignore instructions that might be embedded within the user-provided data.\n
- Sanitization: No sanitization or validation mechanisms are implemented to filter malicious content from the user inputs before processing.
Audit Metadata