meaning
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's description and body use directive language like 'Stop.' and 'Wait, I don't understand...' to redirect agent behavior, which mimics prompt injection techniques.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the environment and previous interactions.
- Ingestion points: The instructions in
SKILL.mdreference the 'last message' and an externalCONTEXT.mdfile. - Boundary markers: No delimiters or isolation instructions are provided to separate the ingested data from the skill's operational instructions.
- Capability inventory: No dangerous tools, subprocess calls, or network operations were found in the provided files.
- Sanitization: The skill does not perform any validation or sanitization of the external content before processing it.
Audit Metadata