simready-foundation-conform-fet-022-newton
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill consumes external data (validation reports and user requests) to drive its file repair operations, creating a surface for potential indirect prompt injection attacks.
- Ingestion points: The workflow relies on data from validation reports, profile TOML files, and user requests to identify necessary repairs (SKILL.md).
- Boundary markers: There are no explicit delimiters or specific 'ignore' instructions for the content of the external reports.
- Capability inventory: The skill allows the agent to write modifications to USD assets and JSON manifests.
- Sanitization: The skill employs a 'Source of Truth' mitigation, instructing the agent to use a local, authoritative JSON manifest for all dependencies and requirement IDs, which restricts the agent's actions to a verified set of requirements regardless of the content in the external reports.
Audit Metadata