etymology-and-word-origins-expert

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a research checklist that directs the agent to ingest data from external sources and use it to update its core guidance modules.
  • Ingestion points: In modules/research-checklist.md, the agent is instructed to use tools to fetch data from Wikipedia and Arxiv.
  • Boundary markers: The instructions lack markers or specific warnings to ignore embedded instructions within the research data, which increases the risk of the agent following malicious commands found in those sources.
  • Capability inventory: The agent is explicitly directed to "Update modules/core-guidance.md" based on the results of the external research, allowing untrusted data to potentially modify the skill's future instructions.
  • Sanitization: No validation or sanitization steps are defined for the content retrieved from external sources before it is incorporated into the skill's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 05:38 PM
Security Audit — agent-trust-hub — etymology-and-word-origins-expert