setting-detector
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to "listen" to user input for specific keywords to automatically trigger the
Readtool for loading external reference files. This ingestion of untrusted data into control logic presents a vulnerability surface. - Ingestion points: User-provided story descriptions and dialogue are analyzed for keywords defined in the mapping table (found in
SKILL.md). - Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to distinguish between narrative content and potential commands embedded in user text.
- Capability inventory: The skill utilizes the
Readtool to load markdown files from thetemplates/knowledge-base/directory. - Sanitization: No sanitization or strict validation of the triggered keywords is defined to prevent an attacker from attempting to influence which files are loaded into the agent's context.
- [SAFE]: The skill operates within the scope of its intended purpose as a writing assistant. It uses the
Readtool to access its own internal knowledge base files. No network operations, access to sensitive system directories (such as.sshor.aws), or arbitrary command execution were identified in the analyzed content.
Audit Metadata