seda-spec
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data sources to generate its output, creating a potential surface for indirect prompt injection.\n
- Ingestion points: Conversation logs, issue trackers, policy documents, and existing specifications referenced in the input.\n
- Boundary markers: The agent is instructed to distinguish between "confirmed behavior" and "inference," and to document "confirmed authority" versus "unresolved questions," which provides a logical structure to identify and isolate untrusted content.\n
- Capability inventory: The skill can invoke sub-agents and use the
akosiletool to write to workspace records.\n - Sanitization: There are no explicit instructions for sanitizing or escaping the input data before processing.\n\n- [COMMAND_EXECUTION]: The instructions describe interactions with external tools and sub-agents to perform specialized tasks.\n
- Evidence: The skill delegates work to sub-agents named
amose,iwadi,arojinle, andarchitect. It also records behavior specifications via theakosiletool using specific parameters (owner: seda-spec,record_type: behavior-spec). These represent standard modular agent interactions within the vendor's ecosystem.
Audit Metadata