ladder-refine
Pass
Audited by Gen Agent Trust Hub on Feb 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- PROMPT_INJECTION (LOW): Indirect Prompt Injection surface detected. The skill processes user-supplied specification files and has filesystem write capabilities. * Ingestion points: SKILL.md reads user-provided spec files. * Boundary markers: Absent. * Capability inventory: File-write (SKILL.md Phase D.5) and git commit execution. * Sanitization: Absent.
Audit Metadata