style-detector
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied keywords to select and load external style guides from the path
.claude/knowledge-base/styles/. The content of these files is then incorporated into the agent's context, which could potentially contain instructions that influence agent behavior.\n- Ingestion points: User query keywords and the content of style guide files as described in SKILL.md and EXAMPLES.md.\n- Boundary markers: The skill lacks explicit boundary markers or instructions to ignore embedded commands within the loaded style guide content.\n- Capability inventory: The skill utilizes the Read tool to access local knowledge base files and the Edit tool to update the specification.md configuration file.\n- Sanitization: There is no evidence of sanitization or validation of the loaded file content before it is interpolated into the prompt context.
Audit Metadata