idea-creator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute local shell sequences and run Python scripts (research_wiki.py and threat_scan.py) to manage reference data and launch parallel background experiments. These capabilities are intended for the skill's primary function but involve local command execution risks.
  • [INDIRECT_PROMPT_INJECTION]: The skill introduces a clear indirect prompt injection surface because it aggregates untrusted external information from web searches, web fetches, and local query files, which is then interpolated directly into brainstorming bundles evaluated by secondary LLMs.
  • Ingestion points: External data is collected via WebSearch, WebFetch, and by reading research-wiki/query_pack.md within SKILL.md.
  • Boundary markers: The workflow implements a defensive check that passes query_pack.md through a threat scanner before reading it, and references external hygiene files (injection-hygiene.md).
  • Capability inventory: Includes broad shell execution via Bash, file reading/writing, parallel background job management, and multi-model tool routing (mcp__codex__codex, mcp__manual_review__review).
  • Sanitization: Relies on an external threat_scan.py file to validate local files, but lacks explicit string escaping or structural sandboxing for web content before it is processed by the model.
  • [PROMPT_INJECTION]: Text within Phase 0 dictates specific required formats for 'verdict-bearing manual responses' and directs the system to 'emit REVIEW_UNAVAILABLE'. These meta-instructions can act as prompt overrides or cause execution confusion depending on how the host system processes the raw instruction text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — idea-creator