simready-foundation-conform-fet-006-mdl
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external sources such as profile TOML files, validation reports, and user requests to identify and repair conformance issues, creating an attack surface for indirect prompt injection.
- Ingestion points:
SKILL.md(Workflow Step 1) specifies loading data from profile TOML, validation reports, and user requests to identify the feature and version. - Boundary markers: The instructions do not specify any delimiters or warnings to the agent to ignore instructions that might be embedded within the processed reports or profiles.
- Capability inventory: The skill has the capability to read local project files (
nv_core/tiers/...), write to staged output locations (SKILL.mdStep 4), and execute validation gates (SKILL.mdStep 6). - Sanitization: There is no mention of input sanitization or validation of the content within the profile TOML or validation reports before processing.
Audit Metadata