idea-discovery-robot
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided input through the
$ARGUMENTSvariable and interpolates it directly into sub-skill commands and search queries without using boundary markers or sanitization. This creates a surface where a malicious prompt embedded in a robotics direction could influence the behavior of the agent or its tools. - Ingestion points: User input provided via
$ARGUMENTSinSKILL.md. - Boundary markers: None provided for the interpolated input.
- Capability inventory: The skill has access to
Bash(*),Write,Edit,WebSearch,WebFetch, and external MCP tools (mcp__codex__codex). - Sanitization: No validation or filtering is performed on the input before processing.
- [METADATA_POISONING]: The skill's configuration defines a non-existent model,
gpt-6-astra, as theREVIEWER_MODEL. This is deceptive metadata that misleads the agent or the user regarding the actual intelligence and capabilities being utilized during the review phase.
Audit Metadata