long-task-control
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to its requirement to ingest and process external task data. \n- Ingestion points: The skill instructs the agent to read "actual artifacts, checks, remaining work, history or rollout, and active agents" in SKILL.md. \n- Boundary markers: There are no explicit instructions or delimiters defined to isolate the ingested content or to warn the agent against following instructions embedded within those artifacts. \n- Capability inventory: The agent is granted the authority to "interrupt an active delegate", "re-decompose the remaining work", and "retire stale agents" based on its evaluation of the ingested content. \n- Sanitization: The skill lacks any requirement for escaping, filtering, or validating external content before it influences decision-making.\n- [NO_CODE]: The skill does not include any executable scripts, binaries, or external code dependencies, which limits its operational surface to the interpretation of natural language instructions.
Audit Metadata