chaos-recon
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection through its data ingestion process.
- Ingestion points: The skill instructions (SKILL.md) direct the agent to gather context by reading architecture documents, incident history, and chaos tooling configurations.
- Boundary markers: There are no explicit boundary markers or instructions provided to the agent to treat the content of these external files as untrusted data or to ignore embedded instructions.
- Capability inventory: The skill is granted powerful capabilities including 'Bash' for shell command execution, 'Write' for modifying the filesystem, and 'WebFetch' for network operations.
- Sanitization: The skill does not define any sanitization, filtering, or validation steps for the content ingested from the local repository files.
Audit Metadata