ralph
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input by interpolating it directly into the output context.
- Ingestion points: User-provided input is injected via the
{{ARGUMENTS}}placeholder inSKILL.md. - Boundary markers: Absent. The input is placed directly after a "Task:" label without delimiters or instructions for the agent to ignore embedded commands.
- Capability inventory: This specific file does not define executable scripts or tool calls; it functions as a documentation and redirection stub.
- Sanitization: Absent. There is no evidence of escaping or validation performed on the interpolated data.
Audit Metadata