simready-foundation-add-capability
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data to generate documentation and code files.
- Ingestion points: User-provided parameters such as
display_name,scope, andinitial_requirementsare collected in theInputssection ofSKILL.md. - Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from obeying malicious instructions embedded within the provided input data.
- Capability inventory: The skill has the capability to create new directories and write to multiple files, including
.mddocumentation and.pysource files. - Sanitization: While the skill suggests naming conventions (e.g., snake_case), it lacks explicit sanitization or escaping rules for content interpolated into the files.
- [DYNAMIC_EXECUTION]: The skill generates Python source code files based on templates and user inputs.
- Evidence: Step 7 of the instructions in
SKILL.mddirects the agent to create avalidation.pyfile with imports and a placeholder structure. The generation of executable source files from potentially untrusted inputs is a documented security surface.
Audit Metadata