advanced-elicitation

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external content to apply reasoning methods, which presents a surface for indirect prompt injection.
  • Ingestion points: The {content} placeholder used in all elicitation method templates in SKILL.md.
  • Boundary markers: Templates consistently use triple-dash delimiters (---) to isolate the injected content from the reasoning instructions.
  • Capability inventory: The skill has access to Read and Write tools as specified in the YAML frontmatter.
  • Sanitization: No explicit programmatical sanitization or escaping of the {content} variable is defined in the instructions.
  • [EXTERNAL_DOWNLOADS]: The skill references several external research frameworks and papers to support its reasoning models.
  • Sources: Includes links to official repositories and publications from well-known organizations such as Meta AI, Stanford University, and Google. These references are used to provide theoretical grounding for the skill's methods and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 11:22 AM
Security Audit — agent-trust-hub — advanced-elicitation