judge
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies and ingests untrusted data from the conversation history and local workspace files to evaluate them using sub-agents.
- Ingestion points: Extracts evaluation context from the conversation history, including original tasks, work outputs, and specific file contents (SKILL.md, Phase 1 & 3).
- Boundary markers: Uses specific tags like
[ORIGINAL TASK],[WORK OUTPUT], and[FILES INVOLVED], as well as YAML code blocks, to delimit external content within prompts sent to sub-agents (SKILL.md, Phase 3). - Capability inventory: The skill uses the
Tasktool to launch sub-agents (sadd:meta-judge,sadd:judge), transferring the ingested context to them. - Sanitization: Relies on a context extraction step to filter data before passing it to sub-agents, though it does not explicitly mention character escaping or sanitization of the artifact content.
Audit Metadata