visual-companion
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes content from discovery plans to adapt its layout suggestions, which presents an indirect prompt injection surface.\n
- Ingestion points: The skill reads the most recent file in exploration/discovery-plans/ to establish context and determine output types (SKILL.md).\n
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to isolate potentially malicious instructions within the discovery plans.\n
- Capability inventory: The skill has Read and Write capabilities, including the ability to write confirmed layout directions to exploration/captures/layout-direction.md and trigger transitions to the exploration-workflow skill.\n
- Sanitization: Content from discovery plans is processed directly without specific filtering or escaping mechanisms to prevent instruction override.
Audit Metadata