handsfree
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions designed to override standard agent safety and interaction protocols. By declaring that confirmation questions such as 'Should I continue?' are 'banned' and that 'Continuation is implicit', the skill instructs the agent to disregard standard human-in-the-loop safeguards.
- [INDIRECT_PROMPT_INJECTION]: The autonomous mode established by the skill increases the risk that the agent will execute instructions hidden in untrusted data without user verification. 1. Ingestion points: Any data processed by tool calls while the 'handsfree' policy is active (SKILL.md). 2. Boundary markers: Absent; the skill does not provide instructions to distinguish between user intent and instructions embedded in external data. 3. Capability inventory: The policy governs all available tools, including terminal commands and file modifications (references/antigravity.md). 4. Sanitization: No sanitization or validation mechanisms are defined to check autonomous decisions against potentially malicious data inputs.
Audit Metadata