philosophy
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides a
/philosophy checkcommand that evaluates 'current work' for alignment with Oracle principles. This ingestion of untrusted data constitutes a surface for indirect prompt injection. \n - Ingestion points: The
/philosophy checkcommand inSKILL.mdprocesses current work content. \n - Boundary markers: Absent; the skill does not specify delimiters or instructions to ignore embedded commands in the processed data. \n
- Capability inventory: The skill utilizes the
dateshell utility and internal tools such asarra_traceandarra_learn. \n - Sanitization: No sanitization or validation of the input work is described. \n- [COMMAND_EXECUTION]: The skill includes instructions to run the
datecommand to provide a timestamp for responses. This is a standard administrative function and is considered safe.
Audit Metadata