simready-foundation-conform-fet-004-physx
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exposes an attack surface where malicious instructions could be embedded in the data it processes.
- Ingestion points: In
SKILL.md, the workflow (Step 1 and 2) explicitly instructs the agent to read and identify data from a "profile TOML, validation report, or user request," as well as source assets. - Boundary markers: The instructions lack explicit boundary markers or warnings to the agent to ignore potentially malicious instructions embedded within the processed reports or assets.
- Capability inventory: The skill allows for file system modifications ("Repair only the requirements...") and command execution ("Rerun the same profile gate or the narrowest available feature/capability validation gate") based on the processed inputs.
- Sanitization: No sanitization, escaping, or validation steps for external content are defined before it influences the agent's write or execution actions.
Audit Metadata