alcatchup
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on external files to define its execution protocol, creating an ingestion surface where untrusted content could influence agent behavior.
- Ingestion points: The skill reads from
../alignfirst/SKILL.mdandreferences/catchup-protocol.md. - Boundary markers: Absent. There are no markers or instructions to isolate or ignore potentially malicious content within the referenced files.
- Capability inventory: The skill directs the agent to "Execute the catchup protocol," which may involve tool usage or complex logic defined in the external files.
- Sanitization: Absent. The skill does not perform any validation or filtering of the content loaded from the external references.
- [PROMPT_INJECTION]: The skill contains instructions that explicitly override the agent's standard operating procedures.
- Evidence: The directive "Do not use your own plan mode" modifies the agent's reasoning process and autonomy.
Audit Metadata