adversarial-prompting
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to automatically run a local script,
scripts/export_analysis.py, which interacts with the host's file system. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided problem descriptions and processes them to generate analysis, which is then saved to disk, potentially persisting malicious instructions or exfiltrated data.
- Ingestion points: User-supplied problem descriptions processed in the 7-phase workflow.
- Boundary markers: None identified; the skill does not use specific delimiters or instructions to ignore embedded commands in the input data.
- Capability inventory: The skill has the capability to write files to the user's home directory via the bundled Python script.
- Sanitization: The export script sanitizes the filename to allow only alphanumeric characters, but the analysis content itself is written to the file without sanitization or escaping.
Audit Metadata