tradecraft-attack-scenarios
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill outlines a methodology where the agent ingests external target data to build a sequenced attack plan, creating a surface for indirect prompt injection. 1. Ingestion points: The agent is instructed to enumerate surfaces from recon (recon-*) and read scope information from scope.txt. 2. Boundary markers: The skill does not define delimiters or specific instructions for the agent to ignore embedded commands within the target data. 3. Capability inventory: The agent is instructed to write an ordered strategy to plan.md and execute multiple sequential tradecraft techniques. 4. Sanitization: No sanitization, validation, or filtering of reconnaissance findings is specified in the planning phase.
- [NO_CODE]: The skill consists of YAML frontmatter and Markdown instructions for the agent's behavior, with no accompanying scripts, binaries, or automation code.
Audit Metadata