invention-structuring

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: User-provided $ARGUMENTS and local files including patent/INVENTION_BRIEF.md, patent/PRIOR_ART_REPORT.md, and patent/NOVELTY_ASSESSMENT.md (documented in the 'Inputs' section of SKILL.md).
  • Boundary markers: The skill does not define specific delimiters or "ignore embedded instructions" warnings for the ingested content.
  • Capability inventory: The skill is configured with broad tool access including Bash(*), Write, Edit, and mcp__codex__codex (specified in the YAML frontmatter).
  • Sanitization: There is no evidence of filtering, escaping, or validation of the input data before it is processed or passed to the external mcp__codex__codex tool in Step 6.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:07 AM
Security Audit — agent-trust-hub — invention-structuring