campfire

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted data from multiple sources without sanitization.\n
  • Ingestion points: SKILL.md (Step 2 in 'Before You Begin' scans names and descriptions of installed skills; Step 4 checks recent activity in calendar, project management, and messaging tools).\n
  • Boundary markers: Absent. The skill does not define delimiters to separate external tool outputs from the agent's internal instructions.\n
  • Capability inventory: The skill uses the retrieved data to generate character dialogue and 'campfire' interactions across the session.\n
  • Sanitization: Absent. There is no validation or filtering of the content retrieved from external tools or skill metadata before it is used to influence the agent's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:39 PM
Security Audit — agent-trust-hub — campfire