think-frame-creation
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process a user-supplied "problem" description as its primary input to generate a new problem frame. This constitutes a surface for indirect prompt injection where untrusted data enters the agent context.
- Ingestion points: The input problem is ingested in
SKILL.mdunder Instruction 1 and processed through thematic analysis. - Boundary markers: The instructions do not specify the use of delimiters or specific "ignore embedded instructions" warnings for the user-supplied problem text.
- Capability inventory: The skill possesses no capabilities for subprocess calls, code execution, file writing, or network operations across any of its scripts.
- Sanitization: There is no explicit sanitization or filtering of the external content described in the instructions.
- Assessment: Because the skill lacks any dangerous capabilities that could be triggered by malicious instructions in the input data, the risk associated with this surface is negligible.
Audit Metadata