refine-critique-loop
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external 'artifacts' using file-read operations which serves as an ingestion point for untrusted data.
- Ingestion points: The
inspectstage uses thefile-readatom to ingest content from existing artifacts into the agent context. - Boundary markers: The instructions in
SKILL.mdlack explicit delimiters or warnings to ignore potential instructions embedded within the design artifacts being refined. - Capability inventory: The skill possesses
fs:readandfs:writecapabilities, and utilizes atoms likepatch-editanddiff-reviewwhich could be manipulated by malicious content in a processed file. - Sanitization: There is no evidence of sanitization or filtering applied to the content read from artifacts before it is processed by the refinement loop.
Audit Metadata