meta-self
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses authoritative language to mandate a specific logic framework for all subsequent agent actions. Phrases such as "authoritative reference for the categorical meta-prompting framework," "All commands and skills should align with this specification," and "Categorical Laws (Must Be Satisfied)" serve as meta-instructions that attempt to override the agent's standard operating procedures.
- [INDIRECT_PROMPT_INJECTION]: The skill introduces a complex Domain Specific Language (DSL) including powerful operators and modifiers (e.g.,
/chain,@catch:substitute,→, Kleisli composition). If the agent processes untrusted data that contains these symbols or command patterns, it may interpret them as framework instructions rather than literal data. - Ingestion points: The framework primarily processes "task descriptions" provided in strings within
SKILL.mdor as command arguments. - Boundary markers: The skill suggests using quotes and brackets for tasks, but does not provide instructions to the agent on how to handle framework-like syntax found inside those tasks.
- Capability inventory: The documentation describes capabilities for code review, systematic debugging, API design, and multi-agent orchestration (e.g.,
/hekat,/task-relay,/review). - Sanitization: The skill lacks explicit sanitization guidelines for the agent when interpolating untrusted task descriptions into the categorical execution flow.
Audit Metadata