skills/meisijiya/skills/loop-me/Gen Agent Trust Hub

loop-me

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user data from the NOTES.md file to guide its interactive session and generate workflow specifications, creating a surface for indirect prompt injection.
  • Ingestion points: The skill explicitly reads the NOTES.md file located in the user's workspace to establish the context for the workflow design.
  • Boundary markers: No specific delimiters or instructions to ignore embedded instructions are defined for the content ingested from the NOTES.md file.
  • Capability inventory: The skill has access to powerful tools, including Bash, Write, and Edit, providing a potential pathway for follow-on actions if an injection were to occur.
  • Sanitization: The instructions do not specify any validation, filtering, or sanitization procedures for the text data imported from the workspace notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:14 AM
Security Audit — agent-trust-hub — loop-me