skills/udaysharmadev/skills/distill/Gen Agent Trust Hub

distill

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to transform vague or underspecified user requests into structured task briefs. This process involves interpreting untrusted user input and incorporating it into documentation that serves as instructions for future agent actions, creating a potential vector for indirect prompt injection.\n
  • Ingestion points: The skill ingests arbitrary user feature requests as the primary input and performs lightweight repository reads for context, as specified in the 'Workflow' section of SKILL.md.\n
  • Boundary markers: There are no specific instructions for the agent to use XML-like delimiters or 'ignore embedded instructions' warnings when processing the user's input into the brief template.\n
  • Capability inventory: The skill reads repository files for grounding and writes generated markdown files to the docs/briefs/ directory (SKILL.md, Output contract).\n
  • Sanitization: The skill lacks explicit instructions for sanitizing or filtering user input to prevent the inclusion of malicious instructions or executable command strings in the 'Verification' or 'Acceptance Criteria' sections of the generated brief.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 08:07 PM
Security Audit — agent-trust-hub — distill