dhdna-profiler

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it analyzes untrusted, user-provided text without adequate safety boundaries.
  • Ingestion points: Untrusted data enters the agent context whenever a user provides text for cognitive profiling (SKILL.md).
  • Boundary markers: The skill does not define or utilize delimiters or specific instructions to ignore embedded commands within the text being analyzed.
  • Capability inventory: The skill is granted 'Read' and 'Write' tool permissions to extract thinking patterns and output formatted profiles.
  • Sanitization: The instructions do not include requirements for input sanitization or validation of the text before the profiling process begins.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 05:14 PM