redteam
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input via the $ARGUMENTS variable to conduct its analysis, which defines a vulnerability surface for indirect prompt injection.
- Ingestion points: The target data for analysis enters the agent context through the $ARGUMENTS placeholder at the end of SKILL.md.
- Boundary markers: The skill does not use specific delimiters or instructions to ignore potential commands embedded within the analyzed content.
- Capability inventory: The skill does not invoke any external tools, scripts, or network operations, limiting the risk associated with successful injection.
- Sanitization: There is no validation or filtering of the user-supplied input before it is interpolated into the prompt.
Audit Metadata