olofofo
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and follow instructions from external files located at
.qp/EMI.mdand~/.qp/EMI.md. This creates a vector where content from these files can steer the agent's behavior. Ingestion points: Files.qp/EMI.mdand~/.qp/EMI.md(SKILL.md). Boundary markers: Instructions state that EMI files are subordinate to system safety and developer authority. Capability inventory: Writing HTML reports to~/.qp/report/, updating wisdom indices in~/.qp/OGBON.md, and invoking other skills likehtml-artifactandIwadi(SKILL.md, cross-session-learning.md). Sanitization: The skill explicitly instructs the agent to ignore prompt-like commands within theOGBON.mdevidence files. - [PERSISTENCE_MECHANISMS]: The file
references/global-activation.mdcontains instructions for the agent to modify the host's global instruction file to ensure the skill activates in every session. This functions as a persistence mechanism for agent behavior across the entire workspace. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill aggregates session activity, including links to local and remote artifacts, into a single HTML file stored in
~/.qp/report/. While the instructions forbid including credentials or secrets, the aggregation of session metadata in a persistent format increases the risk associated with local data exposure.
Audit Metadata