develop-topic
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions specify that the agent should perform experiments to settle claims, which involves defining and running a "command" and recording its results in
content/experiments/<name>.md. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process "sourced facts", "interpretations", and "primary material" from external research. It lacks explicit boundary markers or sanitization steps to handle potentially malicious instructions embedded in that external research data, which could influence the agent's behavior during the content development process.
- Ingestion points: External research sources and primary materials recorded in
RESEARCH.md. - Boundary markers: None identified.
- Capability inventory: File system writes (creating the
content/structure) and command execution for verification experiments. - Sanitization: None specified.
- [DYNAMIC_EXECUTION]: The agent dynamically determines the method and "command" needed to verify research claims at runtime based on the subject matter, representing a form of script generation and execution from researched data.
Audit Metadata