sumeru-finalize
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary novel text from the
chapters/directory, creating a surface for instructions embedded within that data to be executed by the agent. - Ingestion points: Reads novel content from the
chapters/directory for processing and validation. - Boundary markers: The instructions do not specify any delimiters or safety prompts to isolate the novel content from the agent's control logic.
- Capability inventory: The skill has the capability to write files to the
.sumeru/finalize/andpublish/directories and perform batch/regex-based text transformations. - Sanitization: There is no documented validation or sanitization of the input text to prevent the processing of malicious payloads or hidden instructions.
Audit Metadata