featuring-nomination
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted user content and processes it into output files.\n
- Ingestion points: App details, developer stories, and user impact narratives are collected via the
AskUserQuestiontool inSKILL.md.\n - Boundary markers: No boundary markers or 'ignore embedded instructions' warnings are present to isolate user input from the agent's operational logic.\n
- Capability inventory: The skill utilizes
Write,Edit, andWebSearchtools during the generation process inSKILL.md.\n - Sanitization: User-provided text is interpolated directly into the nomination template without escaping, validation, or filtering.
Audit Metadata