simready-foundation-conform-fet-022-physx
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, including validation reports, profile TOML files, and asset metadata, which could serve as vectors for indirect prompt injection.
- Ingestion points: The workflow in
SKILL.mdrequires the agent to read and confirm inputs from profile TOML files, validation reports, and requirement documents. - Boundary markers: The instructions lack explicit boundary markers or directions for the agent to ignore natural language instructions embedded within the processed data.
- Capability inventory: The skill is authorized to perform file modifications ("repairs") and staged file writes, providing a mechanism for an injection to affect the local filesystem.
- Sanitization: There is no mention of sanitization, filtering, or validation logic to distinguish between legitimate data and potential instructions in the input files.
Audit Metadata