loop-me
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill manages files strictly within the
workflows/directory and theNOTES.mdfile. Its capabilities (create, edit, delete) are consistent with its stated purpose of refining workflow specifications during a user interview session. - [INDIRECT_PROMPT_INJECTION]: The skill features an ingestion surface for potentially untrusted data:
- Ingestion points: Reads from
NOTES.mdand existing specifications inworkflows/*.md(SKILL.md). - Boundary markers: Absent; the instructions do not implement specific delimiters to isolate file content from prompt instructions.
- Capability inventory: The skill can write to and modify files within the defined workspace (SKILL.md).
- Sanitization: No validation or sanitization of the input file content is performed. While these factors create an injection surface, the risk is assessed as safe because the content is intended to be user-authored notes within a private workspace.
Audit Metadata