think-random-frameworks
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill identifies and reads local framework skill files based on a selection logic calculated from user input (topic length or a seed).
- Evidence:
references/engine.mdStep A instructions specify opening frameworks by slug from the localskills/directory. The selection range is restricted to a pre-defined corpus inrecommendable.json. - [INDIRECT_PROMPT_INJECTION]: The skill functions as an orchestrator that passes user-provided topics to multiple other framework skills.
- Ingestion points: User-supplied topic input defined in
SKILL.mdinstructions. - Boundary markers: The shared engine does not specify the use of delimiters or boundary markers when interpolating user topics into secondary skills.
- Capability inventory: The skill is limited to local file read operations and text generation; it has no network access or shell execution privileges.
- Sanitization: No specific input validation or sanitization of the user topic is described.
Audit Metadata