pie-fluid-systems

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection through its data ingestion pipeline.
  • Ingestion points: Data enters the agent's context from external files matching the *.calc and *.pid patterns defined in the frontmatter.
  • Boundary markers: The skill does not implement delimiters or 'ignore' instructions to isolate user-provided data from the agent's core instructions.
  • Capability inventory: Across all referenced materials, the skill maintains access to the Bash tool for running calculations and scripts, which increases the potential impact of an injection.
  • Sanitization: There is no evidence of content filtering or validation for the data ingested from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:15 PM
Security Audit — agent-trust-hub — pie-fluid-systems