trace
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill serves as an orchestration layer that ingests and analyzes untrusted data from multiple external sources.
- Ingestion points: The skill accepts a user-provided observation via the
<observation to trace>argument and directs agents to gather evidence from external sources including logs, source code, configurations, and tool outputs liketrace_timelineandtrace_summary(SKILL.md). - Boundary markers: The instructions lack explicit requirements for agents to use delimiters or 'ignore embedded instructions' markers when processing external data.
- Capability inventory: The agent environment includes capabilities for reading files, accessing logs, and retrieving system trace information to validate hypotheses.
- Sanitization: There are no defined protocols for sanitizing or filtering potentially malicious instructions that could be embedded within the logs or code artifacts being analyzed.
Audit Metadata