skill-agent-topology
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by design. It is intended to ingest and analyze potentially untrusted data such as multi-agent workflow transcripts and run directories.
- Ingestion points: The skill explicitly requests "a transcript or run directory" as input for measurement-based audits.
- Boundary markers: Absent. The instructions do not define specific delimiters or provide guidance to the agent to disregard instructions that may be embedded within the audited transcripts.
- Capability inventory: The skill focus is on logical reasoning and report generation. While it mentions the use of the Codex shell and subagent tools, it does not directly invoke specific high-privilege tool calls or network operations using the ingested content.
- Sanitization: The skill lacks mechanisms to sanitize or validate the external content before it is interpolated into the agent's context for analysis.
Audit Metadata