sleuth
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions involve analyzing external data such as logs, stack traces, and database content, which are potential ingestion points for indirect prompt injection. 1. Ingestion points: Analyzing error logs, stack traces, and database records (SKILL.md Step 4; references/techniques.md). 2. Boundary markers: The skill does not provide specific instructions for using delimiters to isolate untrusted data. 3. Capability inventory: The agent is instructed to perform file reads, log analysis, and database queries to gather evidence (SKILL.md Step 4; references/techniques.md). 4. Sanitization: No sanitization or filtering of ingested data is described. As this surface is inherent to the debugging process, it is documented as a functional surface and does not impact the safety verdict.
Audit Metadata