daily-review
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the way it handles untrusted conversation history data.
- Ingestion points: The skill ingests potentially untrusted content via the
conversationsfield in the input JSON structure described in SKILL.md. - Boundary markers: The prompt instructions do not include any delimiters (such as XML tags, unique separators, or explicit boundary markers) or safety directives telling the model to ignore instructions embedded within the text of the conversation logs.
- Capability inventory: Based on the SKILL.md file, the skill does not request any tool permissions (allowed-tools) or include executable scripts, which limits the impact of a potential injection.
- Sanitization: There is no evidence of data sanitization, filtering, or escaping performed on the conversation data before it is presented to the LLM for analysis.
Audit Metadata