nutmeg
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting data from external and potentially untrusted sources while maintaining access to sensitive capabilities.\n
- Ingestion points: The skill retrieves content from the internet via the
WebFetchandWebSearchtools and reads local project files including.nutmeg.user.md,docs/entity-resolution-routing.md, anddocs/accuracy-guardrail.md.\n - Boundary markers: The instructions lack explicit delimiters or specific warnings for the agent to treat data from these external or file-based sources as untrusted or to ignore embedded instructions.\n
- Capability inventory: The skill is authorized to use powerful tools including
Bashfor command execution,Writefor file modification, andAgentfor delegating tasks to other specialized assistants.\n - Sanitization: There are no defined procedures for sanitizing, validating, or escaping content retrieved from web sources or project files before it influences agent routing logic or tool parameters.
Audit Metadata