frame
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads from external documentation files to guide its planning process, creating a surface where malicious instructions in those files could influence the agent's behavior.
- Ingestion points: The process instructions reference reading content from design-docs/NN-name.alignment.md and design-docs/NN-name.research.md.
- Boundary markers: There are no instructions provided to use delimiters or ignore instructions embedded within these external files.
- Capability inventory: The skill's primary capabilities include reading local files and writing a new frame.md planning document to the design-docs/ directory.
- Sanitization: The skill does not include steps to sanitize or validate the content of the external files before processing them.
Audit Metadata