skills/1git2clone/dotfiles/the-fool/Gen Agent Trust Hub

the-fool

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided positions, plans, or architectures from the conversation history, creating a surface for indirect prompt injection.
  • Ingestion points: The core workflow in SKILL.md (Step 1) extracts the user's position directly from the conversation context to restate it for analysis.
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore potential commands embedded within the user's provided thesis.
  • Capability inventory: The skill is limited to conversational interaction and loading internal reference documents; it uses the AskUserQuestion tool but lacks capabilities for file modification, network communication, or shell execution.
  • Sanitization: There is no evidence of validation or sanitization routines for the extracted user content before it is processed by the agent's reasoning modes.
  • [NO_CODE]: The skill consists entirely of instructional Markdown files and methodology references. No executable scripts (Python, JavaScript, shell) or external binary dependencies are included in the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — the-fool