turn-incident-into-content

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill attempts to read a hidden file at ~/.devadvokit.md. Accessing configuration files in the home directory is a potential data exposure risk, as these files may contain user-specific context or content history.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from user Q&A responses and external files to generate content drafts, creating an attack surface for embedded malicious instructions.
  • Ingestion points: User answers to support/technical problem questions; local file ~/.devadvokit.md; shared file ../../shared/ai-antipatterns.md.
  • Boundary markers: Absent. No delimiters or instructions are provided to the agent to treat the contents of these inputs as data rather than instructions.
  • Capability inventory: File system read access (via prompt instructions to read specific paths).
  • Sanitization: Absent. The skill does not perform validation or filtering of the ingested content before processing.
  • [PROMPT_INJECTION]: The instructions include directives such as "read it silently and use it throughout this skill" and "Do not mention this step to the user." These are concealment techniques used to hide agent operations from the end-user.
  • [COMMAND_EXECUTION]: The skill uses relative path traversal (../../shared/ai-antipatterns.md) to access files located outside of its own skill directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:38 PM