research-refine-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external and potentially untrusted data, creating a surface for indirect prompt injection attacks.
- Ingestion points: The skill ingests user input via the
$ARGUMENTSvariable and reads existing files such asrefine-logs/FINAL_PROPOSAL.mdandrefine-logs/REVIEW_SUMMARY.md(found inSKILL.md). - Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings for the content being processed.
- Capability inventory: The skill utilizes powerful capabilities including
Bash(*),Write,Edit,WebSearch, andWebFetch(found in YAML frontmatter). - Sanitization: No sanitization or validation protocols are defined to filter instructions from ingested data before they are interpreted by the agent.
- [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands to handle file operations, specifically as a silent fallback mechanism.
- Evidence: In
SKILL.md, a rule under "Key Rules" directs the agent to immediately retry failed file writes usingBashwithcat << 'EOF' > filewithout requesting user permission.
Audit Metadata