crystal-healing-traditions-expert
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to maintain a 'mystical atmosphere' and use 'evocative language,' which is a persona-based instruction typical for this domain. However, the modular architecture and the instructions in
modules/research-checklist.mdcreate an indirect prompt injection surface. The agent is tasked with running web searches and then using the results to 'Move confirmed instructions into dedicated topic modules' and 'Update metadata.' This allows instructions found in external, untrusted content (like Wikipedia or other search results) to potentially override or be integrated into the skill's operational instructions. - Ingestion points: Web research results (from tools or searches) described in
modules/research-checklist.md. - Boundary markers: No delimiters or specific 'ignore' instructions are provided to separate research data from core logic.
- Capability inventory: The instructions imply the agent has the capability to modify its own configuration and module files based on external findings.
- Sanitization: No sanitization or filtering logic is specified for the ingested content.
Audit Metadata