simready-foundation-add-feature
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to generate documentation, JSON manifests, and even new skill definitions, which creates a potential surface for indirect prompt injection if downstream processes interpret data in those files as instructions.
- Ingestion points: The skill collects several user-defined fields including
runtime_promise,display_name,requirements, andfeature_idfrom the initial request. - Boundary markers: There are no instructions to wrap these user-supplied values in boundary markers or include warnings for subsequent agents to ignore instructions embedded in these fields.
- Capability inventory: The skill instructions involve extensive file-writing capabilities, including creating new markdown files, JSON manifests, and creating a new
SKILL.mdfor a conform skill, as well as updating theassets/openai.yamlindex. - Sanitization: The instructions lack specific guidance on sanitizing or escaping user-provided text before it is interpolated into the generated files.
Audit Metadata