frame-board
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface.
- Ingestion points: The skill reads project documents and external web data via WebFetch (SKILL.md, Step 1).
- Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard potential instructions in the source data.
- Capability inventory: The skill is authorized to use Bash, Write, and WebFetch tools.
- Sanitization: There is no instruction to sanitize or validate the content retrieved from external sources before processing.
Audit Metadata