cheat-persona
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It ingests 'top comments' from external data sources (predictions/*.md) and processes this untrusted text to generate reports in audience.md. Malicious instructions embedded in these comments could influence the agent's output.
- Ingestion points: predictions/*.md (comments section).
- Boundary markers: None specified for external data.
- Capability inventory: Write, Edit, Read.
- Sanitization: Not explicitly implemented in the instructions.
Audit Metadata