workshop
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for the agent to read and process arbitrary local files such as PDFs and proposals in Track B.
- Ingestion points: Content from local documents provided by the user in the working directory.
- Boundary markers: The instructions lack explicit delimiters or instructions to treat ingested file content as untrusted data.
- Capability inventory: The skill uses the Claude Code environment, which includes capabilities for shell command execution and file system modifications.
- Sanitization: No specific sanitization or filtering logic is provided for the content read from external documents.
Audit Metadata