figure-description

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external files which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Processes patent/INVENTION_DISCLOSURE.md, patent/CLAIMS.md, and various image files (PNG, JPG, SVG, PDF) discovered in the project directory using the Glob and Read tools.
  • Boundary markers: Lacks explicit delimiters or instructions to ignore embedded prompts within the processed patent documentation.
  • Capability inventory: The skill is configured with broad tool access including Bash(*), Write, Edit, WebSearch, and WebFetch.
  • Sanitization: No validation or sanitization steps are defined for the content extracted from the external documents before they are used to generate outputs or mapping indexes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:08 AM
Security Audit — agent-trust-hub — figure-description