think-futures-wheel
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists exclusively of markdown instructions, templates, and metadata files. It does not perform any system commands, network operations, or access the local filesystem.- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by design, as it requires the agent to process user-provided changes or decisions and generate logical ripples.
- Ingestion points: User-provided topics, changes, or decisions provided as input to the agent (defined in
SKILL.md). - Boundary markers: The instructions do not provide explicit delimiters or instructions to ignore nested commands within the user's input.
- Capability inventory: None. The skill has no access to tools, network, or filesystem, meaning that even a successful injection would lack the primitives to cause harm.
- Sanitization: No validation or sanitization is performed on the user-supplied content before it is interpolated into the map generation process.
Audit Metadata