swot
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data through the
$ARGUMENTSplaceholder in bothSKILL.mdandcommands/swot.mdwithout employing boundary markers or sanitization. - Ingestion points: User input is ingested via the
$ARGUMENTSparameter which is appended to the instructions inSKILL.mdandcommands/swot.md. - Boundary markers: None present. The skill does not use delimiters (like XML tags or triple quotes) or explicit instructions to ignore commands embedded within the user-provided analysis subject.
- Capability inventory: As the skill does not restrict tool access in its frontmatter, it retains access to the agent's default capabilities, which typically include filesystem access, shell execution, and network operations.
- Sanitization: There is no evidence of input validation, escaping, or filtering for the data passed into
$ARGUMENTS.
Audit Metadata