careful
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill introduces an indirect prompt injection surface by accepting an optional
scope noteargument from the user and writing it to a persistent session state file (production/session-state/safety-mode.md) without sanitization or boundary markers. This creates a surface where a malicious payload in the scope note could influence the agent's behavior when it later reads the session state. - Ingestion points:
[optional: scope note]argument defined inSKILL.md. - Boundary markers: Absent; the input is written directly into the markdown state file without delimiters or instructions to ignore embedded commands.
- Capability inventory:
Read,Write,Edit, andAskUserQuestiontools are allowed; no shell or direct execution tools are requested. - Sanitization: No sanitization or validation of the scope note input is performed before storage.
Audit Metadata