idea-ingest

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process untrusted external data (articles, tweets, web pages) and perform complex operations based on that content, such as analysis and cross-linking.
  • Ingestion points: The skill uses the get_page tool and other fetching mechanisms to retrieve external content from user-provided URLs (Phase 1).
  • Capability inventory: The agent has permissions to search the knowledge base (search, query), write new pages (put_page), upload files (file_upload), and create links (add_link, add_timeline_entry).
  • Boundary markers: There are no instructions for using delimiters or boundary markers (e.g., XML tags or specific prefixes) to isolate the untrusted external content from the agent's system instructions.
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation steps for the fetched content before it is processed for analysis or saved to the brain, leaving the agent susceptible to instructions hidden within the source material.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 06:17 PM
Security Audit — agent-trust-hub — idea-ingest