oceanography-specialist
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection in
modules/research-checklist.mdby instructing the agent to perform web research and incorporate findings from external sources. - Ingestion points: External data is ingested through web searches and external tools mentioned in
modules/research-checklist.md(e.g., Wikipedia and Arxiv distillers). - Boundary markers: There are no defined delimiters or instructions to treat external data as untrusted text within the workflow.
- Capability inventory: The agent is directed to use research findings to "Update metadata" and "Update modules" (including
modules/core-guidance.md), which involves writing or modifying its own configuration and instructions. - Sanitization: No sanitization or validation mechanisms are specified for the content retrieved from external sources before it is processed.
Audit Metadata