research
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external primary sources and writes to the local repository, which provides a surface for indirect prompt injection attacks. 1. Ingestion points: The agent is instructed to read external content including official documentation, source code, and APIs (referenced in SKILL.md). 2. Boundary markers: The skill does not explicitly instruct the agent to ignore or delimit instructions found within the researched materials. 3. Capability inventory: The agent has the capability to write Markdown files to the repository (referenced in SKILL.md). 4. Sanitization: There is no mention of sanitizing or validating the content retrieved from external sources before processing it or writing it to the repository.
Audit Metadata