build-talk-outline
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is instructed to silently check for and read a local file at
~/.devadvokit.mdto establish speaker context. Accessing dotfiles in the user's home directory is a form of data exposure that could potentially incorporate sensitive personal information into the agent's working context without explicit user confirmation of the file's contents. - [INDIRECT_PROMPT_INJECTION]: The skill combines local speaker context with untrusted user input (CFP abstracts and talk descriptions) to generate a structured talk outline, creating an attack surface where instructions embedded in the user-supplied text could be followed by the agent.
- Ingestion points: User-provided CFP abstracts and descriptions; local configuration file
~/.devadvokit.md. - Boundary markers: Absent. The skill does not use delimiters or provide specific instructions to the agent to distinguish between data and potentially malicious instructions within the user-supplied talk descriptions.
- Capability inventory: The skill uses the agent to generate structured text and perform timing analysis. The configuration does not restrict tool access, meaning the agent operates with its default capability set.
- Sanitization: There is no mechanism to sanitize, validate, or filter the user input before it is processed by the model along with the local context.
Audit Metadata