think-top3
Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The shared engine (references/engine.md) implements a dynamic loading mechanism where it reads a local corpus (recommendable.json) and then opens and follows instructions from other skill files at paths derived from the corpus slugs (skills/think-/SKILL.md). This represents dynamic execution and loading from computed paths.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input and processes it through a multi-step chain of other framework skills. Ingestion points: The 'topic' provided by the user in SKILL.md. Boundary markers: Present in the final output template (references/TEMPLATE.md) but absent when passing the topic to the dynamically selected sub-frameworks in references/engine.md. Capability inventory: The skill reads local files and instructs the agent to execute other skill logic; sub-frameworks in the catalog may have additional capabilities like file writing or network access. Sanitization: Absent; the user-provided topic is not sanitized or escaped before being interpolated into the instructions for the selected frameworks.
Audit Metadata