simready-foundation-add-feature

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to generate documentation, JSON manifests, and even new skill definitions, which creates a potential surface for indirect prompt injection if downstream processes interpret data in those files as instructions.
  • Ingestion points: The skill collects several user-defined fields including runtime_promise, display_name, requirements, and feature_id from the initial request.
  • Boundary markers: There are no instructions to wrap these user-supplied values in boundary markers or include warnings for subsequent agents to ignore instructions embedded in these fields.
  • Capability inventory: The skill instructions involve extensive file-writing capabilities, including creating new markdown files, JSON manifests, and creating a new SKILL.md for a conform skill, as well as updating the assets/openai.yaml index.
  • Sanitization: The instructions lack specific guidance on sanitizing or escaping user-provided text before it is interpolated into the generated files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-add-feature