using-ltk
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- PROMPT_INJECTION (LOW): The skill uses aggressive, absolute imperatives to override the agent's autonomy and standard reasoning processes.
- Evidence: Phrases like "ABSOLUTELY MUST", "not negotiable", and "not optional" are used to force tool usage.
- The skill explicitly instructs the agent to ignore its own internal logic or safety filters if they conflict with the mandate, labeling these thoughts as "Red Flags" or "rationalizing."
- INDIRECT_PROMPT_INJECTION (LOW): The skill mandates a "1% chance" threshold for invoking the
Skilltool, which significantly increases the likelihood of the agent processing malicious instructions embedded in untrusted external files. - Ingestion points: The
Skilltool loads content from the local or platform environment. - Boundary markers: The skill lacks any instructions to treat the content of loaded skills as untrusted data or to maintain safety boundaries during invocation.
- Capability inventory: The skill references
SkillandTodoWritetools, and suggests the agent follow loaded skill content "exactly." - Sanitization: No sanitization or validation of the invoked skill content is mentioned.
Audit Metadata