develop-topic

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions specify that the agent should perform experiments to settle claims, which involves defining and running a "command" and recording its results in content/experiments/<name>.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process "sourced facts", "interpretations", and "primary material" from external research. It lacks explicit boundary markers or sanitization steps to handle potentially malicious instructions embedded in that external research data, which could influence the agent's behavior during the content development process.
  • Ingestion points: External research sources and primary materials recorded in RESEARCH.md.
  • Boundary markers: None identified.
  • Capability inventory: File system writes (creating the content/ structure) and command execution for verification experiments.
  • Sanitization: None specified.
  • [DYNAMIC_EXECUTION]: The agent dynamically determines the method and "command" needed to verify research claims at runtime based on the subject matter, representing a form of script generation and execution from researched data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:37 PM
Security Audit — agent-trust-hub — develop-topic