research
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, which can be used to influence the agent's behavior via hidden instructions.
- Ingestion points:
SKILL.mdspecifies that the agent should investigate primary sources including official documentation, source code, and first-party APIs. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to ignore or isolate instructions potentially contained within the processed external data.
- Capability inventory: The agent has the capability to write files to the repository's filesystem as specified in
SKILL.md(item 3). - Sanitization: The skill does not define any mechanisms for sanitizing, filtering, or validating the content retrieved from external sources before processing it.
Audit Metadata