careful

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill introduces an indirect prompt injection surface by accepting an optional scope note argument from the user and writing it to a persistent session state file (production/session-state/safety-mode.md) without sanitization or boundary markers. This creates a surface where a malicious payload in the scope note could influence the agent's behavior when it later reads the session state.
  • Ingestion points: [optional: scope note] argument defined in SKILL.md.
  • Boundary markers: Absent; the input is written directly into the markdown state file without delimiters or instructions to ignore embedded commands.
  • Capability inventory: Read, Write, Edit, and AskUserQuestion tools are allowed; no shell or direct execution tools are requested.
  • Sanitization: No sanitization or validation of the scope note input is performed before storage.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — careful