energy-compute-arbitrage

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to process external data (energy prices and cloud costs), creating an indirect prompt injection surface.
  • Ingestion points: External pricing APIs and cloud instance metadata as described in SKILL.md.
  • Boundary markers: The instructions do not define delimiters for external data or specify that the agent should ignore instructions embedded within that data.
  • Capability inventory: The skill specifies capabilities for migrating data and re-routing processing workloads.
  • Sanitization: No sanitization or validation steps are defined for the incoming telemetry and pricing data.
  • [NO_CODE]: The analyzed skill contains only markdown instructions and metadata. It does not include any executable scripts, configuration files, or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 05:40 AM
Security Audit — agent-trust-hub — energy-compute-arbitrage