build-talk-outline

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is instructed to silently check for and read a local file at ~/.devadvokit.md to establish speaker context. Accessing dotfiles in the user's home directory is a form of data exposure that could potentially incorporate sensitive personal information into the agent's working context without explicit user confirmation of the file's contents.
  • [INDIRECT_PROMPT_INJECTION]: The skill combines local speaker context with untrusted user input (CFP abstracts and talk descriptions) to generate a structured talk outline, creating an attack surface where instructions embedded in the user-supplied text could be followed by the agent.
  • Ingestion points: User-provided CFP abstracts and descriptions; local configuration file ~/.devadvokit.md.
  • Boundary markers: Absent. The skill does not use delimiters or provide specific instructions to the agent to distinguish between data and potentially malicious instructions within the user-supplied talk descriptions.
  • Capability inventory: The skill uses the agent to generate structured text and perform timing analysis. The configuration does not restrict tool access, meaning the agent operates with its default capability set.
  • Sanitization: There is no mechanism to sanitize, validate, or filter the user input before it is processed by the model along with the local context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:38 PM