competition-prompt-injection
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and map untrusted content, which could contain malicious instructions meant to subvert the agent's behavior.
- Ingestion points: Untrusted content, retrieved chunks, memory summaries, and transcripts entering the model context as described in SKILL.md and references/prompt-injection.md.
- Boundary markers: No explicit delimiters or system-level instructions to ignore embedded commands are present in the skill's logic.
- Capability inventory: The skill does not define or request specific tools or scripts with dangerous capabilities.
- Sanitization: No logic for sanitizing or escaping the 'untrusted content' is provided within the skill files.
Audit Metadata