state-inconsistency-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted source code provided in the agent context. It includes capabilities to write findings to the local filesystem in the
.audit/findings/directory. Although this constitutes an attack surface for indirect prompt injection, it is the fundamental purpose of the diagnostic tool and is constrained to local operations. - [SAFE]: The skill's instructions are purely analytical and do not contain any patterns for remote code execution, credential exfiltration, or obfuscation. All file operations are directed toward local audit logs, and the skill includes an anti-hallucination protocol to ensure findings are evidence-based.
Audit Metadata