source-to-skill-distiller
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external content (documents, transcripts, codebases), creating a potential indirect prompt injection vulnerability.\n
- Ingestion points: Ingests notes, documents, PDFs, transcripts, videos, courses, repositories, workflows, and chat logs (SKILL.md, description).\n
- Boundary markers: The workflow emphasizes logical boundaries (Workflow step 1, Rule source-skill-1), but does not mandate technical delimiters to isolate external content from instruction context.\n
- Capability inventory: The agent can author and patch repository files and execute local validation scripts (Workflow step 8, references/source-to-skill-patterns.md).\n
- Sanitization: No specific sanitization or escaping mechanisms for external content are defined beyond original synthesis.
Audit Metadata