brainstorm

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes multiple markdown files from the workspace as part of its core logic, which creates a potential surface for indirect prompt injection if those files contain adversarial instructions.
  • Ingestion points: The agent reads content from problem-statement.md, ideas.md, current-understanding.md, results.md, paper-summary.md, literature.md, and clarified-goal.md.
  • Boundary markers: The skill does not define specific delimiters or warnings to treat ingested content as data rather than instructions.
  • Capability inventory: The skill is limited to reading files in the reaper-workspace/ and reaper/references/ directories and writing to reaper-workspace/notes/ideas.md.
  • Sanitization: There is no explicit sanitization or filtering of the content read from these files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 AM
Security Audit — agent-trust-hub — brainstorm