pie-fluid-systems
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection through its data ingestion pipeline.
- Ingestion points: Data enters the agent's context from external files matching the
*.calcand*.pidpatterns defined in the frontmatter. - Boundary markers: The skill does not implement delimiters or 'ignore' instructions to isolate user-provided data from the agent's core instructions.
- Capability inventory: Across all referenced materials, the skill maintains access to the
Bashtool for running calculations and scripts, which increases the potential impact of an injection. - Sanitization: There is no evidence of content filtering or validation for the data ingested from external files.
Audit Metadata