nutmeg-brainstorm

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could potentially contain malicious instructions intended to influence the agent's behavior.
  • Ingestion points: In Phase 2 of SKILL.md, the skill uses WebSearch and WebFetch to retrieve content from external sites, including social media (Twitter/X) and GitHub.
  • Boundary markers: The skill contains a 'Security' section in SKILL.md instructing the agent to treat external content as untrusted, but it lacks specific structural delimiters or markers to isolate this content within the prompt context.
  • Capability inventory: As defined in the frontmatter of SKILL.md, the skill has access to powerful tools including Bash, Write, Agent, and WebFetch.
  • Sanitization: There are no explicit instructions in SKILL.md for the agent to sanitize or escape the external content before reporting it or using it to propose visualization approaches.
  • [EXTERNAL_DOWNLOADS]: The skill fetches a registry catalogue from the author's infrastructure (campos.withqwerty.com) to provide relevant visualization components for React environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 03:24 PM
Security Audit — agent-trust-hub — nutmeg-brainstorm