tradecraft-attack-scenarios

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines a methodology where the agent ingests external target data to build a sequenced attack plan, creating a surface for indirect prompt injection. 1. Ingestion points: The agent is instructed to enumerate surfaces from recon (recon-*) and read scope information from scope.txt. 2. Boundary markers: The skill does not define delimiters or specific instructions for the agent to ignore embedded commands within the target data. 3. Capability inventory: The agent is instructed to write an ordered strategy to plan.md and execute multiple sequential tradecraft techniques. 4. Sanitization: No sanitization, validation, or filtering of reconnaissance findings is specified in the planning phase.
  • [NO_CODE]: The skill consists of YAML frontmatter and Markdown instructions for the agent's behavior, with no accompanying scripts, binaries, or automation code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — tradecraft-attack-scenarios