tree-of-thoughts
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to initialize its workspace by creating specific directories (
.specs/research,.specs/reports) usingmkdir -pto store intermediate reasoning files. - [INDIRECT_PROMPT_INJECTION]: The skill defines a complex workflow where user-supplied task descriptions and context are interpolated into prompts for multiple sub-agents (explorers, judges, and synthesizers).
- Ingestion points: Placeholders such as
{task_description}and{relevant_context}inSKILL.mdare used to build prompts for sub-agents across all five phases. - Boundary markers: The instructions use XML-like tags (e.g.,
<task>,<selected_proposal>) to delimit external content, which provides a layer of separation but does not entirely eliminate injection risks. - Capability inventory: The skill has the capability to spawn sub-agents using different models (Opus, Sonnet) and perform file system write operations for research artifacts.
- Sanitization: No explicit sanitization or filtering of the user-provided strings is documented before they are passed to the sub-agent prompts.
Audit Metadata