skills/4444j99/a-i--skills/qa-audit/Gen Agent Trust Hub

qa-audit

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of session transcripts and artifacts read from disk.
  • Ingestion points: The skill instructions specify reading "referenced session transcripts/artifacts fresh from disk" in SKILL.md and its historical variant.
  • Boundary markers: No explicit delimiters, tags, or instructions are provided to help the agent distinguish between transcript data and potential instructions embedded within that data.
  • Capability inventory: The skill description indicates the ability to read files and verify state (such as git commits) on the local filesystem.
  • Sanitization: The instructions do not define any validation, filtering, or escaping mechanisms for the contents of the processed transcripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — qa-audit