do-competitively

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection risk surface because it directly forwards user-supplied task descriptions and contexts to parallel sub-agents (generators, meta-judges, and multi-perspective judges) without applying explicit validation or sanitization rules.
  • Ingestion points: The {Original task description from user} and {task_description} placeholders in SKILL.md ingest raw external inputs into the workflows for the generators, meta-judge, and judge sub-agents.
  • Boundary markers: The prompt templates utilize XML-like tags (e.g., <task>, <constraints>, <context>) and markdown section headers to establish structural delimiters for the untrusted text.
  • Capability inventory: The orchestrator utilizes the Task tool to invoke parallel sub-agents (sadd:meta-judge, sadd:judge) and triggers local system shell interaction via mkdir -p to store reports.
  • Sanitization: No data filtering, escaping, or character constraints are outlined to prevent adversarial prompts embedded within the task description from tricking downstream sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — do-competitively