route
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a purely instructional and logic-based resource. It provides guidance to the agent on how to categorize decisions and which specialized tools to use for those categories. It does not include any scripts, binaries, or system-level commands.
- [PROMPT_INJECTION]: The skill includes an indirect prompt injection surface as it provides templates for interpolating untrusted user data into tool arguments. 1. Ingestion points: User-provided decisions and plans are ingested via template placeholders like '<decision + options>' or '<the plan/artifact>'. 2. Boundary markers: User input is encapsulated in double quotes within the templates, but no explicit instructions to ignore embedded commands are provided. 3. Capability inventory: The skill directs data to other internal tools such as tribunal, adversarial, or red-team. 4. Sanitization: No explicit validation or filtering of the user-provided data is defined within these instructions.
- [DATA_EXFILTRATION]: There are no patterns suggesting data collection or transmission to external domains.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets or sensitive configuration paths (e.g., .ssh, .aws) are present.
Audit Metadata