idea-creator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute local shell sequences and run Python scripts (
research_wiki.pyandthreat_scan.py) to manage reference data and launch parallel background experiments. These capabilities are intended for the skill's primary function but involve local command execution risks. - [INDIRECT_PROMPT_INJECTION]: The skill introduces a clear indirect prompt injection surface because it aggregates untrusted external information from web searches, web fetches, and local query files, which is then interpolated directly into brainstorming bundles evaluated by secondary LLMs.
- Ingestion points: External data is collected via
WebSearch,WebFetch, and by readingresearch-wiki/query_pack.mdwithinSKILL.md. - Boundary markers: The workflow implements a defensive check that passes
query_pack.mdthrough a threat scanner before reading it, and references external hygiene files (injection-hygiene.md). - Capability inventory: Includes broad shell execution via Bash, file reading/writing, parallel background job management, and multi-model tool routing (
mcp__codex__codex,mcp__manual_review__review). - Sanitization: Relies on an external
threat_scan.pyfile to validate local files, but lacks explicit string escaping or structural sandboxing for web content before it is processed by the model. - [PROMPT_INJECTION]: Text within Phase 0 dictates specific required formats for 'verdict-bearing manual responses' and directs the system to 'emit REVIEW_UNAVAILABLE'. These meta-instructions can act as prompt overrides or cause execution confusion depending on how the host system processes the raw instruction text.
Audit Metadata