wait-what
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from
CONTEXT.mdandCONTEXT-MAP.mdto define terminology. This creates a potential surface for instructions embedded in these files to influence the agent.\n - Ingestion points: The skill reads external glossary files
CONTEXT.mdandCONTEXT-MAP.mdas described in the Contract section ofSKILL.md.\n - Boundary markers: The instructions do not define clear boundaries or delimiters for the ingested file content.\n
- Capability inventory: The skill has no file-write, network, or command execution capabilities;
disable-model-invocationis explicitly set to true.\n - Sanitization: Content from the external files is not sanitized or filtered before processing.\n- [SAFE]: The skill does not contain executable code or perform network operations. All external references are for documentation purposes and point to the author's infrastructure or established development repositories.
Audit Metadata