eos-usage
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external text passed through the
$ARGUMENTSvariable. Because it does not use boundary markers to separate this untrusted input from its own instructions, an attacker could potentially embed malicious prompts within the text under review to influence the agent's behavior. - Ingestion points: Data is ingested via the
$ARGUMENTSplaceholder located at the end of theSKILL.mdfile. - Boundary markers: Absent. The instructions do not define delimiters (such as XML tags, backticks, or specific markers) to isolate the text being reviewed, nor do they include instructions to ignore commands within that text.
- Capability inventory: The skill contains no executable scripts, system commands, network requests, or file system operations; it relies entirely on the agent's native language capabilities.
- Sanitization: No sanitization or validation of the input text is specified.
Audit Metadata