meta-self

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative language to mandate a specific logic framework for all subsequent agent actions. Phrases such as "authoritative reference for the categorical meta-prompting framework," "All commands and skills should align with this specification," and "Categorical Laws (Must Be Satisfied)" serve as meta-instructions that attempt to override the agent's standard operating procedures.
  • [INDIRECT_PROMPT_INJECTION]: The skill introduces a complex Domain Specific Language (DSL) including powerful operators and modifiers (e.g., /chain, @catch:substitute, →, Kleisli composition). If the agent processes untrusted data that contains these symbols or command patterns, it may interpret them as framework instructions rather than literal data.
  • Ingestion points: The framework primarily processes "task descriptions" provided in strings within SKILL.md or as command arguments.
  • Boundary markers: The skill suggests using quotes and brackets for tasks, but does not provide instructions to the agent on how to handle framework-like syntax found inside those tasks.
  • Capability inventory: The documentation describes capabilities for code review, systematic debugging, API design, and multi-agent orchestration (e.g., /hekat, /task-relay, /review).
  • Sanitization: The skill lacks explicit sanitization guidelines for the agent when interpolating untrusted task descriptions into the categorical execution flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:04 PM
Security Audit — agent-trust-hub — meta-self