observe-skill

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to capture and store data from other skills' executions, which represents an indirect injection surface.
  • Ingestion points: The skill ingests task descriptions, 'what worked/failed' summaries, and verbatim error messages or unexpected responses from the agent's context as defined in SKILL.md.
  • Boundary markers: There are no instructions to use boundary markers or delimiters when writing the collected data to the log files.
  • Capability inventory: The skill performs file system write operations to create and append to files in the 'observations/' directory.
  • Sanitization: No sanitization or escaping mechanisms are specified for the external content before it is persisted to disk, allowing potentially malicious payloads within error messages to be stored in the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:34 PM
Security Audit — agent-trust-hub — observe-skill