nutmeg-brainstorm
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could potentially contain malicious instructions intended to influence the agent's behavior.
- Ingestion points: In Phase 2 of
SKILL.md, the skill usesWebSearchandWebFetchto retrieve content from external sites, including social media (Twitter/X) and GitHub. - Boundary markers: The skill contains a 'Security' section in
SKILL.mdinstructing the agent to treat external content as untrusted, but it lacks specific structural delimiters or markers to isolate this content within the prompt context. - Capability inventory: As defined in the frontmatter of
SKILL.md, the skill has access to powerful tools includingBash,Write,Agent, andWebFetch. - Sanitization: There are no explicit instructions in
SKILL.mdfor the agent to sanitize or escape the external content before reporting it or using it to propose visualization approaches. - [EXTERNAL_DOWNLOADS]: The skill fetches a registry catalogue from the author's infrastructure (
campos.withqwerty.com) to provide relevant visualization components for React environments.
Audit Metadata