critique
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user feedback and research documents to direct subsequent agent actions and research phases.\n
- Ingestion points: User-supplied feedback arguments,
reaper-workspace/feedbacks/log files, andreaper-workspace/papers/content.\n - Boundary markers: The skill lacks explicit instructions for using delimiters or boundary markers when interpolating user feedback into the workspace log files (
round-N.md).\n - Capability inventory: The skill can read/write files, call the
codex-cliMCP server, and invoke internal skills likebrainstormandinvestigate, providing a path for injected instructions to influence system-level behaviors.\n - Sanitization: The skill instructions explicitly require copying user feedback "exactly" into workspace files without sanitization, filtering, or escaping, allowing for raw injection of malicious instructions into the research context.
Audit Metadata