clarify
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user inputs, such as vague requests, voice dumps, and rough plans, to generate executable prompts for other agents. This creates a surface where malicious instructions embedded in the user's initial request could be refined into the final prompt and executed by a subsequent agent.
- Ingestion points: Vague requests, voice dumps, rough plans, and referenced repository material (e.g.,
README.md,CLAUDE.md) as specified inSKILL.md. - Boundary markers: The instructions do not prescribe the use of delimiters or 'ignore' directives to prevent the agent from following commands hidden within the input data.
- Capability inventory: The skill itself does not define any script-based capabilities, tool calls, or network operations; it is a text-based instruction set for the agent.
- Sanitization: There are no explicit steps provided to sanitize, validate, or filter user input before it is interpolated into the final prompt structure.
Audit Metadata