executive-brief

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface in SKILL.md (Step 1). It is designed to read and interpolate content from work.local.md into the agent's context for brief generation.
  • Ingestion points: Reads work.local.md in the current working directory (Step 1).
  • Boundary markers: None identified. There are no instructions to the agent to treat content within work.local.md as untrusted data or to ignore embedded instructions.
  • Capability inventory: No risky system capabilities (shell execution, network, etc.) were found in the provided files.
  • Sanitization: No evidence of escaping or filtering content from work.local.md before it is used to generate the situation brief.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 12:17 PM
Security Audit — agent-trust-hub — executive-brief