spec-to-code-compliance
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external content such as protocol whitepapers, Notion exports, meeting transcripts, and source code. A malicious specification could attempt to influence the agent's audit findings through embedded instructions.\n- [INDIRECT_PROMPT_INJECTION]: Ingestion points: Data is ingested in Phase 0 and Phase 3 from external files including
whitepaper.pdf,Protocol.md, and the smart contract codebase.\n- [INDIRECT_PROMPT_INJECTION]: Boundary markers: The instructions employ a structured 7-phase analysis process and require mandatory citation of exact evidence (quotes and line numbers) to ground the agent's reasoning.\n- [INDIRECT_PROMPT_INJECTION]: Capability inventory: The skill performs analytical tasks and generates audit reports; there are no instructions for network exfiltration, subprocess execution, or modification of security settings.\n- [INDIRECT_PROMPT_INJECTION]: Sanitization: Phase 1 includes a normalization process to strip layout noise and styling artifacts from various document formats (PDF, HTML, etc.) before they are analyzed.
Audit Metadata