icp
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes potentially untrusted external content such as product landing pages and onboarding copy, along with internal codebase files. This creates a surface for indirect prompt injection where malicious instructions embedded in these sources could attempt to influence the agent's behavior during the profiling process.
- Ingestion points:
SKILL.md(Workflow Step 1) - The skill reads landing pages, pricing pages, onboarding copy, README files, and the codebase to mine signals.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when interpolating this untrusted data into the prompt context.
- Capability inventory:
SKILL.md(Workflow Step 5) - The skill has the capability to create or update the
.agents/memory/icp.mdfile on the filesystem. - Sanitization: No explicit sanitization, filtering, or validation of the ingested content is described in the workflow to prevent the processing of malicious instructions.
Audit Metadata