create-strategy
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to generate JSON configuration files and CLI commands, creating a potential surface for indirect prompt injection.
- Ingestion points: User input gathered during Phase 1 and Phase 4 (e.g., strategy ID, directional view, risk tolerance) in
SKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore potentially malicious instructions embedded within user-supplied values.
- Capability inventory: The agent generates complete JSON configuration patches (Phase 5, Block A) and shell commands (Phase 4 and Phase 5, Block B) based on interpolated user data.
- Sanitization: No sanitization or validation logic is prescribed to prevent malicious strings from altering the structure of the generated JSON or the logic of the generated shell commands.
Audit Metadata