ten-defeats
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill is composed exclusively of markdown instructions and YAML configuration metadata. It does not include any executable source code, scripts (e.g., Python, JavaScript), or compiled binaries.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external software data (such as codebases, logs, and UI states) and utilizes high-privilege tools that could be influenced by malicious content embedded in that data.\n
- Ingestion points: The skill ingests untrusted data from non-trivial software work, including source code, build logs, and live environment states accessed via browser and desktop UI tools (SKILL.md).\n
- Boundary markers: The instructions lack defined delimiters or specific warnings to ignore instructions embedded within the external software data being analyzed.\n
- Capability inventory: The skill leverages powerful capabilities including Computer Use, browser control, multi-tool coordination, and agent delegation (SKILL.md).\n
- Sanitization: No sanitization or validation mechanisms are described to filter external content before it is processed by the agent's reasoning loop.
Audit Metadata