early-stage-hustle
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION] (LOW): Indirect Prompt Injection Surface. The skill instructs the agent to prioritize content from external files (
references/patterns.md,references/sharp_edges.md, andreferences/validations.md) as the 'source of truth' over user input. This creates an attack surface where instructions embedded in these data files could manipulate the agent's behavior. - Ingestion points:
references/patterns.md,references/sharp_edges.md, andreferences/validations.md(referenced in SKILL.md). - Boundary markers: None identified. There are no instructions to the agent to distinguish between data and potential instructions within these files.
- Capability inventory: No executable scripts or system-level capabilities are defined in this specific file.
- Sanitization: None. The agent is explicitly told to 'Ignore generic approaches' and 'politely correct' users based on these files.
Audit Metadata