think-random-frameworks

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill identifies and reads local framework skill files based on a selection logic calculated from user input (topic length or a seed).
  • Evidence: references/engine.md Step A instructions specify opening frameworks by slug from the local skills/ directory. The selection range is restricted to a pre-defined corpus in recommendable.json.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as an orchestrator that passes user-provided topics to multiple other framework skills.
  • Ingestion points: User-supplied topic input defined in SKILL.md instructions.
  • Boundary markers: The shared engine does not specify the use of delimiters or boundary markers when interpolating user topics into secondary skills.
  • Capability inventory: The skill is limited to local file read operations and text generation; it has no network access or shell execution privileges.
  • Sanitization: No specific input validation or sanitization of the user topic is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:40 PM
Security Audit — agent-trust-hub — think-random-frameworks