think-framework-advisor

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Structural vulnerability to Indirect Prompt Injection. The skill is designed to ingest untrusted user data and interpolate it into executable prompt strings for other agent skills.
  • Ingestion points: User-provided situation descriptions and decision contexts (SKILL.md, references/TEMPLATE.md).
  • Boundary markers: Absent. The instructions for generating the Thinking Plan do not specify the use of delimiters (e.g., XML tags) or 'ignore embedded instructions' warnings around the user-supplied content in the output prompts.
  • Capability inventory: While the skill itself only provides recommendations, it produces 'filled ready-to-run' invocations for a library of over 60 analytical skills (references/recommendable.json) which perform file analysis and reasoning tasks.
  • Sanitization: No explicit sanitization, filtering, or escaping of user input is implemented. The skill relies on a 'mirroring' step for user confirmation, which serves as a manual check but does not mitigate the technical injection surface in the generated command payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 06:16 AM
Security Audit — agent-trust-hub — think-framework-advisor