antislop
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PERSISTENCE]: The skill includes an installation wizard that appends configuration blocks to project-specific agent entry files such as
CLAUDE.md,AGENTS.md, orGEMINI.mdto ensure the rules remain active across sessions. - Evidence: Step 5 of the 'First-Run Install Wizard' describes appending an antislop pointer block to the project's entry file.
- Mitigation: The instructions mandate that the agent must declare the setup and obtain explicit user approval before modifying any files.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external design direction files which could potentially contain conflicting or malicious instructions.
- Ingestion points: The agent is instructed to read
DESIGN.mdor other brand/style direction files provided by the user (R-37). - Boundary markers: The skill includes a dedicated 'Boundary' section that explicitly instructs the agent to treat external file content as data to apply, not as instructions to obey, and to report any contradictions to the user.
- Capability inventory: The skill uses
Read,Write,Edit,Glob, andGreptools to manage design files and configuration. - Sanitization: While no technical sanitization is present, the skill provides logical prompt-based filtering to ignore commands inside data files.
- [EXTERNAL_DOWNLOADS]: The documentation mentions various external installation and update methods using tools like
npx,claude plugin, andpi. - Evidence: The 'Already installed, and the user asks how to update' section lists multiple command-line update paths for different agent environments.
- Mitigation: The skill explicitly instructs the agent that it must not attempt to fetch skills or updates from the network itself, stating that the user must perform these actions manually (Step 4 of the Wizard).
Audit Metadata