evidence-before-claims
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a set of defensive guidelines aimed at improving the accuracy and reliability of security reporting.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle potentially untrusted data from security scanners, external research sources, and malware analysis outputs.
- Ingestion points: Activation triggers include reporting on exploitability, summarizing scanner output, and reverse-engineering findings (e.g., SKILL.md).
- Boundary markers: The skill establishes explicit boundary markers through its 'Evidence Ladder' and 'Wording Discipline', requiring the agent to qualify the strength of its findings.
- Capability inventory: The skill itself contains no executable code, network operations, or file-writing capabilities across the analyzed files.
- Sanitization: It mandates the inspection of primary artifacts (hashes, logs, raw packet captures) and requires byte-for-byte verification of cited files to prevent the agent from being misled by potentially poisoned tool output or subagent summaries.
Audit Metadata