sillytavern-shadow
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The system prompts in both versions employ role-play personas ("Zero-Second Response Shadow Guard") and high-pressure instructional framing ("failure penalty", "competitive mockery"). While these techniques are designed to influence agent behavior and output style, they do not contain instructions to bypass safety guidelines, ignore ethical constraints, or reveal internal system prompts.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user input within the incident description field. 1. Ingestion points: User-provided event descriptions in SKILL.md. 2. Boundary markers: None identified; input is directly interpolated into the system prompt structure. 3. Capability inventory: No internal scripts or tools are provided within the skill files; however, the v2.0 checklist assumes the agent has access to external tools for searching and reading files. 4. Sanitization: No input validation or sanitization logic is present.
- [NO_CODE]: The skill consists entirely of Markdown instructions and YAML metadata. It does not include any executable scripts, configuration files for package managers, or binary assets.
Audit Metadata