asian-fusion-chef
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill establishes a workflow in
modules/research-checklist.mdthat requires the agent to perform targeted web searches and ingest data from external sources like Wikipedia and ArXiv to update its instructions. This creates a surface for indirect prompt injection where malicious content from these external sites could attempt to override agent behavior. - Ingestion points: Defined in
modules/research-checklist.md(targeted web searches, Wikipedia, ArXiv). - Boundary markers: No delimiters or explicit instructions to ignore embedded commands in the ingested data are present.
- Capability inventory: The skill is designed to have the agent write to and update its own instruction modules (
modules/core-guidance.md). - Sanitization: There are no instructions provided for sanitizing or validating the content retrieved from external sources before it is processed or stored.
Audit Metadata