cto
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by instructing the agent to ingest and act upon data from external sources and workspace configuration files without explicit sanitization or boundary markers.
- Ingestion points: Technical data and constraints are read from internal workspace files (
context.md,operator.md,ai-landscape). Additionally, the agent is directed to perform live web searches and consult external provider documentation to verify technical specifications and pricing. - Boundary markers: The instructions do not define specific delimiters or provide guidance for the agent to ignore potentially malicious instructions embedded in these external data sources.
- Capability inventory: The skill is designed for agents with file-reading capabilities and access to web search tools.
- Sanitization: There are no requirements for validating, escaping, or filtering content retrieved from the web before it is processed by the agent.
- [NO_CODE]: The skill consists entirely of instructional text and configuration metadata. It does not contain any executable scripts, binary files, or automated installation commands.
Audit Metadata