setting-detector

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to "listen" to user input for specific keywords to automatically trigger the Read tool for loading external reference files. This ingestion of untrusted data into control logic presents a vulnerability surface.
  • Ingestion points: User-provided story descriptions and dialogue are analyzed for keywords defined in the mapping table (found in SKILL.md).
  • Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to distinguish between narrative content and potential commands embedded in user text.
  • Capability inventory: The skill utilizes the Read tool to load markdown files from the templates/knowledge-base/ directory.
  • Sanitization: No sanitization or strict validation of the triggered keywords is defined to prevent an attacker from attempting to influence which files are loaded into the agent's context.
  • [SAFE]: The skill operates within the scope of its intended purpose as a writing assistant. It uses the Read tool to access its own internal knowledge base files. No network operations, access to sensitive system directories (such as .ssh or .aws), or arbitrary command execution were identified in the analyzed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 10:36 AM
Security Audit — agent-trust-hub — setting-detector