voxel-art
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWPROMPT_INJECTION
Full Analysis
- PROMPT_INJECTION (LOW): The skill instructions mandate the use of external reference files (references/patterns.md, references/sharp_edges.md, references/validations.md) as the source of truth. This creates an indirect prompt injection vector where an attacker who can modify these files could influence the agent output.
- Ingestion points: SKILL.md (Reference System Usage section) references external files for creation, diagnosis, and review rules.
- Boundary markers: Absent; the agent is told to ground responses in these files without specific delimiters or warnings to ignore embedded commands.
- Capability inventory: None detected. The skill is limited to providing art advice and does not possess file-write, network-access, or command-execution capabilities.
- Sanitization: Absent.
Audit Metadata