cheat-persona

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It ingests 'top comments' from external data sources (predictions/*.md) and processes this untrusted text to generate reports in audience.md. Malicious instructions embedded in these comments could influence the agent's output.
  • Ingestion points: predictions/*.md (comments section).
  • Boundary markers: None specified for external data.
  • Capability inventory: Write, Edit, Read.
  • Sanitization: Not explicitly implemented in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 04:05 AM
Security Audit — agent-trust-hub — cheat-persona