test-skill

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill documentation includes template instructions designed to override an agent's standard behavior and reasoning by framing simulated scenarios as 'real' events.\n
  • Evidence: Templates such as 'IMPORTANT: This is a real scenario. Choose and act.' and 'Don't ask hypothetical questions
  • make the actual decision.' are suggested to force agents to ignore their training context and make choices under pressure.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides a framework for embedding instructional steering (pressure scenarios) into the data processed by agents during testing phases.\n
    1. Ingestion points: The SKILL.md file contains examples and templates for these pressure tests in sections like 'RED Phase' and 'VERIFY GREEN'.\n
    1. Boundary markers: The provided templates do not include delimiters or specific instructions to isolate these tests from the agent's core instructions.\n
    1. Capability inventory: The skill is documentation-focused, but it instructs agents to perform actions like deleting code or committing fixes under pressure, which involves file system and version control capabilities in the target environment.\n
    1. Sanitization: No sanitization or validation mechanisms are described for the generated scenarios to prevent them from affecting the agent's global state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — test-skill