brainstorm
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes multiple markdown files from the workspace as part of its core logic, which creates a potential surface for indirect prompt injection if those files contain adversarial instructions.
- Ingestion points: The agent reads content from
problem-statement.md,ideas.md,current-understanding.md,results.md,paper-summary.md,literature.md, andclarified-goal.md. - Boundary markers: The skill does not define specific delimiters or warnings to treat ingested content as data rather than instructions.
- Capability inventory: The skill is limited to reading files in the
reaper-workspace/andreaper/references/directories and writing toreaper-workspace/notes/ideas.md. - Sanitization: There is no explicit sanitization or filtering of the content read from these files.
Audit Metadata