meaning-preserving-rewrite
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external policy documents and official documentation websites, which creates a potential surface for indirect prompt injection attacks. \n
- Ingestion points: External sources are read during the baseline capture phase (SKILL.md) and the documentation inventory phase (references/docs-inventory.md). \n
- Boundary markers: The instructions do not explicitly mandate the use of delimiters or specific 'ignore' instructions when the agent processes external content to prevent the agent from following instructions embedded in that content. \n
- Capability inventory: The skill has capabilities to read and write files (for backups and rewrites) and is instructed to perform network fetches for documentation. \n
- Sanitization: There are no explicit requirements to sanitize or validate the content of the ingested data for embedded malicious prompts.
Audit Metadata