sumeru-polish
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests novel content from the
chapters/directory and uses it to perform file-write operations, creating a vulnerability surface for indirect prompt injection where malicious instructions embedded in the text could influence agent behavior. - Ingestion points: The agent reads existing novel content directly from the
chapters/directory. - Boundary markers: The instructions do not define clear delimiters or specific guidance to ignore instructions embedded within the processed content.
- Capability inventory: The skill has the ability to read from and write to the local file system (modifying
chapters/and creating backups in.sumeru/). - Sanitization: There is no indication of content sanitization or filtering to prevent the execution of embedded prompts.
Audit Metadata