dhdna-profiler
Pass
Audited by Gen Agent Trust Hub on Mar 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it analyzes untrusted, user-provided text without adequate safety boundaries.
- Ingestion points: Untrusted data enters the agent context whenever a user provides text for cognitive profiling (SKILL.md).
- Boundary markers: The skill does not define or utilize delimiters or specific instructions to ignore embedded commands within the text being analyzed.
- Capability inventory: The skill is granted 'Read' and 'Write' tool permissions to extract thinking patterns and output formatted profiles.
- Sanitization: The instructions do not include requirements for input sanitization or validation of the text before the profiling process begins.
Audit Metadata