analyse
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill takes a user-supplied
target_descriptionto drive its analysis process, creating a surface for potential injection from untrusted data. - Ingestion points: The
/analysecommand and theTARGETvariable inSKILL.mdaccept arbitrary user input to define the scope of analysis. - Boundary markers: The instructions do not specify any delimiters (e.g., XML tags or triple quotes) or warnings to the agent to ignore instructions that might be embedded within the target code or description being analyzed.
- Capability inventory: The skill instructs the agent to "Observe reality: Read actual code", "Explore unfamiliar areas", and "Document findings" across various files and system components.
- Sanitization: No input validation, escaping, or filtering is performed on the target description before it is interpolated into the agent's reasoning process.
Audit Metadata