skill-comply
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external instruction artifacts to derive agent behavior specifications and run test scenarios.
- Ingestion points: The skill ingests a path to a SKILL.md, rule file, command, agent definition, or instruction doc, along with scenario lists and trace logs as described in the contract section of SKILL.md.
- Boundary markers: There are no defined boundary markers or explicit instructions to ignore embedded commands within the ingested artifacts to prevent the agent from obeying instructions found inside the data being evaluated.
- Capability inventory: The skill has the capability to run local agent commands, execute tests, and write local report files as specified in the External Side Effects section of SKILL.md.
- Sanitization: No sanitization, validation, or escaping logic is specified for the content of the processed files before they influence the agent's evaluation and reporting actions.
Audit Metadata