advanced-elicitation
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external content to apply reasoning methods, which presents a surface for indirect prompt injection.
- Ingestion points: The
{content}placeholder used in all elicitation method templates inSKILL.md. - Boundary markers: Templates consistently use triple-dash delimiters (
---) to isolate the injected content from the reasoning instructions. - Capability inventory: The skill has access to
ReadandWritetools as specified in the YAML frontmatter. - Sanitization: No explicit programmatical sanitization or escaping of the
{content}variable is defined in the instructions. - [EXTERNAL_DOWNLOADS]: The skill references several external research frameworks and papers to support its reasoning models.
- Sources: Includes links to official repositories and publications from well-known organizations such as Meta AI, Stanford University, and Google. These references are used to provide theoretical grounding for the skill's methods and are documented neutrally.
Audit Metadata