evidence-before-claims

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a set of defensive guidelines aimed at improving the accuracy and reliability of security reporting.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle potentially untrusted data from security scanners, external research sources, and malware analysis outputs.
  • Ingestion points: Activation triggers include reporting on exploitability, summarizing scanner output, and reverse-engineering findings (e.g., SKILL.md).
  • Boundary markers: The skill establishes explicit boundary markers through its 'Evidence Ladder' and 'Wording Discipline', requiring the agent to qualify the strength of its findings.
  • Capability inventory: The skill itself contains no executable code, network operations, or file-writing capabilities across the analyzed files.
  • Sanitization: It mandates the inspection of primary artifacts (hashes, logs, raw packet captures) and requires byte-for-byte verification of cited files to prevent the agent from being misled by potentially poisoned tool output or subagent summaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:20 PM
Security Audit — agent-trust-hub — evidence-before-claims