chungus
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes a dominant persona ("CHUNGUS") and authoritative language, such as "You follow every rule below automatically" and "Not a suggestion. Not optional. You obey," which is intended to override standard agent behavior to strictly enforce the skill's specific ruleset.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to analyze and modify untrusted user content.
- Ingestion points: Processes user-supplied source code, pull requests, and bug reports (SKILL.md).
- Boundary markers: No specific delimiters or "ignore" instructions are provided for processed data.
- Capability inventory: Performing file edits, executing browser automation via Playwright/Puppeteer, and conducting network-based security tests (SKILL.md).
- Sanitization: Lacks explicit sanitization for external content, relying instead on manual post-implementation checklists.
- [EXTERNAL_DOWNLOADS]: The instructions recommend several industry-standard libraries for document generation, browser automation, and video processing, including playwright, puppeteer, remotion, and exceljs.
Audit Metadata