result-report-generator
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from experiment artifacts which could contain malicious instructions.\n
- Ingestion points: The skill reads
run_summary.json, method cards, probe summaries, decision ledgers, metrics tables, and the sessionrigor_profile(SKILL.md).\n - Boundary markers: The instructions lack specific guidance on using delimiters (such as XML tags) or system instructions to ignore embedded commands within the ingested files.\n
- Capability inventory: The agent can write markdown reports to the file system, move directories in the workspace, and trigger follow-up tools like
decision-prompt-builder.\n - Sanitization: No sanitization or validation logic is specified for the content extracted from the input artifacts.
Audit Metadata