loop-me
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user data from the
NOTES.mdfile to guide its interactive session and generate workflow specifications, creating a surface for indirect prompt injection. - Ingestion points: The skill explicitly reads the
NOTES.mdfile located in the user's workspace to establish the context for the workflow design. - Boundary markers: No specific delimiters or instructions to ignore embedded instructions are defined for the content ingested from the
NOTES.mdfile. - Capability inventory: The skill has access to powerful tools, including
Bash,Write, andEdit, providing a potential pathway for follow-on actions if an injection were to occur. - Sanitization: The instructions do not specify any validation, filtering, or sanitization procedures for the text data imported from the workspace notes.
Audit Metadata