analyse

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill takes a user-supplied target_description to drive its analysis process, creating a surface for potential injection from untrusted data.
  • Ingestion points: The /analyse command and the TARGET variable in SKILL.md accept arbitrary user input to define the scope of analysis.
  • Boundary markers: The instructions do not specify any delimiters (e.g., XML tags or triple quotes) or warnings to the agent to ignore instructions that might be embedded within the target code or description being analyzed.
  • Capability inventory: The skill instructs the agent to "Observe reality: Read actual code", "Explore unfamiliar areas", and "Document findings" across various files and system components.
  • Sanitization: No input validation, escaping, or filtering is performed on the target description before it is interpolated into the agent's reasoning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — analyse