do-competitively
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection risk surface because it directly forwards user-supplied task descriptions and contexts to parallel sub-agents (generators, meta-judges, and multi-perspective judges) without applying explicit validation or sanitization rules.
- Ingestion points: The
{Original task description from user}and{task_description}placeholders inSKILL.mdingest raw external inputs into the workflows for the generators, meta-judge, and judge sub-agents. - Boundary markers: The prompt templates utilize XML-like tags (e.g.,
<task>,<constraints>,<context>) and markdown section headers to establish structural delimiters for the untrusted text. - Capability inventory: The orchestrator utilizes the
Tasktool to invoke parallel sub-agents (sadd:meta-judge,sadd:judge) and triggers local system shell interaction viamkdir -pto store reports. - Sanitization: No data filtering, escaping, or character constraints are outlined to prevent adversarial prompts embedded within the task description from tricking downstream sub-agents.
Audit Metadata