journey-map
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. * Ingestion points: The skill is instructed to ingest data from code files, transcripts, support tickets, and external URLs (SKILL.md). * Boundary markers: The instructions do not specify the use of delimiters or boundary markers to isolate untrusted content from system instructions. * Capability inventory: The agent has file-read capabilities and file-write capabilities for creating documentation in docs/service-design/ (SKILL.md). * Sanitization: No sanitization or validation steps are described for handling external data or URL content.
- [EXTERNAL_DOWNLOADS]: The skill instructions involve ingesting content from external URLs, which involves network operations to non-whitelisted domains.
Audit Metadata