adversarial-prompting

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to automatically run a local script, scripts/export_analysis.py, which interacts with the host's file system.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided problem descriptions and processes them to generate analysis, which is then saved to disk, potentially persisting malicious instructions or exfiltrated data.
  • Ingestion points: User-supplied problem descriptions processed in the 7-phase workflow.
  • Boundary markers: None identified; the skill does not use specific delimiters or instructions to ignore embedded commands in the input data.
  • Capability inventory: The skill has the capability to write files to the user's home directory via the bundled Python script.
  • Sanitization: The export script sanitizes the filename to allow only alphanumeric characters, but the analysis content itself is written to the file without sanitization or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:35 AM
Security Audit — agent-trust-hub — adversarial-prompting